Study and Mitigation of Origin Stripping Vulnerabilities in Hybrid-postMessage Enabled Mobile Applications
Guangliang Yang, Jeff Huang, Guofei Gu, Abner Mendoza
Abstract
postMessage is popular in HTML5 based web apps to allow the communication between different origins. With the increasing popularity of the embedded browser (i.e., WebView) in mobile apps (i.e., hybrid apps), postMessage has found utility in these apps. However, different from web apps, hybrid apps have a unique requirement that their native code (e.g., Java for Android) also needs to exchange messages with web code loaded in Web-View. To bridge the gap, developers typically extend postMessage by treating the native context as a new frame, and allowing the communication between the new frame and the web frames. We term such extended postMessage "hybrid postMessage" in this paper. We find that hybrid postMessage introduces new critical security flaws: all origin information of a message is not respected or even lost during the message delivery in hybrid postMessage. If adversaries inject malicious code into WebView, the malicious code may leverage the flaws to passively monitor messages that may contain sensitive information, or actively send messages to arbitrary message receivers and access their internal functionalities and data. We term the novel security issue caused by hybrid postMessage "Origin Stripping Vulnerability" (OSV). In this paper, our contributions are fourfold. First, we conduct the first systematic study on OSV. Second, we propose a lightweight detection tool against OSV, called OSV-Hunter. Third, we evaluate OSV-Hunter using a set of popular apps. We found that 74 apps implemented hybrid postMessage, and all these apps suffered from OSV, which might be exploited by adversaries to perform remote real-time microphone monitoring, data race, internal data manipulation, denial of service (DoS) attacks and so on. Several popular development frameworks, libraries (such as the Facebook React Native framework, and the Google cloud print library) and apps (such as Adobe Reader and WPS office) are impacted. Lastly, to mitigate OSV from the root, we design and implement three new postMessage APIs, called OSV-Free. Our evaluation shows that OSV-Free is secure and fast, and it is generic and resilient to the notorious Android fragmentation problem. We also demonstrate that OSV-Free is easy to use, by applying OSV-Free to harden the complex "Facebook React Native" framework. OSV-Free is open source, and its source code and more implementation and evaluation details are available online.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b949cc10-f7d6-48c2-b8be-7a9fe2e01346Cited by top-tier papers8
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang et al.CCS 2020 · 48 citations
- Understanding Open Ports in Android Applications: Discovery, Diagnosis, and Security AssessmentDaoyuan Wu, Debin Gao, Rocky K. C. Chang, En He et al.NDSS 2019 · 25 citations
- Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context VulnerabilitiesGuangliang Yang, Jeff Huang, Guofei GuUSENIX Security 2019 · 21 citations
- An Empirical Study of Web Resource Manipulation in Real-world Mobile ApplicationsXiaohan Zhang, Yuan Zhang, Qianqian Mo, Hao Xia et al.USENIX Security 2018 · 15 citations
- ωTest: WebView-Oriented Testing for Android ApplicationsJiajun Hu, Lili Wei, Yepang Liu, Shing-Chi CheungISSTA 2023 · 8 citations
Builds on5
- Are these Ads Safe: Detecting Hidden Attacks through the Mobile App-Web InterfacesVaibhav Rastogi, Rui Shao, Yan Chen, Xiang Pan et al.NDSS 2016 · 81 citations
- Automated Generation of Event-Oriented Exploits in Android Hybrid AppsGuangliang Yang, Jeff Huang, Guofei GuNDSS 2018 · 79 citations
- Same-Origin Policy: Evaluation in Modern BrowsersJörg Schwenk, Marcus Niemietz, Christian MainkaUSENIX Security 2017 · 52 citations
- Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViewsTongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen et al.CCS 2017 · 47 citations
- Draco: A System for Uniform and Fine-grained Access Control for Web Code on AndroidGüliz Seray Tuncay, Soteris Demetriou, Carl A. GunterCCS 2016 · 43 citations
Related papers
- PMForce: Systematically Analyzing postMessage Handlers at ScaleMarius Steffens, Ben StockCCS 2020 · 23 citations
- Tabbed Out: Subverting the Android Custom Tab Security ModelPhilipp Beer, Marco Squarcina, Lorenzo Veronese, Martina LindorferS&P 2024 · 7 citations
- Cross-Boundary Mobile Tracking: Exploring Java-to-JavaScript Information Diffusion in WebViewsSohom Datta, Michalis Diamantaris, Ahsan Zafar, Junhua Su et al.NDSS 2026 · 2 citations
- Plain Text, Plain Risks: Measuring HTTP Inclusion in Android WebViews at ScalePhilipp Beer, Sebastian Roth, Martina Lindorfer, Marco SquarcinaUSENIX Security 2026
- ReuNify: A Step Towards Whole Program Analysis for React Native Android AppsYonghui Liu, Xiao Chen, Pei Liu, John Grundy et al.ASE 2023 · 7 citations
