Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViews
Tongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen, XiaoFeng Wang, Luyi Xing, Xiaolong Bai, Nan Zhang, Xinhui Han
Abstract
As a critical feature for enhancing user experience, cross-app URL invocation has been reported to cause unauthorized execution of app components. Although protection has already been put in place, little has been done to understand the security risks of navigating an app's WebView through an URL, a legitimate need for displaying the app's UI during cross-app interactions. In our research, we found that the current design of such cross-WebView navigation actually opens the door to a cross-app remote infection, allowing a remote adversary to spread malicious web content across different apps' WebView instances and acquire stealthy and persistent control of these apps. This new threat, dubbed Cross-App WebView Infection (XAWI), enables a series of multi-app, colluding attacks never thought before, with significant real world impacts. Particularly, we found that the remote adversary can collectively utilize multiple infected apps' individual capabilities to escalate his privileges on a mobile device or orchestrate a highly realistic remote Phishing attack (e.g., running a malicious script in Chrome to stealthily change Twitter's WebView to fake Twitter's own login UI). We show that the adversary can easily find such attack "building blocks" (popular apps whose WebViews can be redirected by another app) through an automatic fuzz, and discovered about 7.4% of the most popular apps subject to the XAWI attacks, including Facebook, Twitter, Amazon and others. Our study reveals the contention between the demand for convenient cross-WebView communication and the need for security control on the channel, and makes the first step toward building OS-level protection to safeguard this fast-growing technology.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d44efe02-7f5c-42e8-8b95-e01c69929ef9Cited by top-tier papers14
- Dangerous Skills: Understanding and Mitigating Security Risks of Voice-Controlled Third-Party Functions on Virtual Personal Assistant SystemsNan Zhang, Xianghang Mi, Xuan Feng, XiaoFeng Wang et al.S&P 2019 · 160 citations
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang et al.CCS 2020 · 48 citations
- Study and Mitigation of Origin Stripping Vulnerabilities in Hybrid-postMessage Enabled Mobile ApplicationsGuangliang Yang, Jeff Huang, Guofei Gu, Abner MendozaS&P 2018 · 27 citations
- Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context VulnerabilitiesGuangliang Yang, Jeff Huang, Guofei GuUSENIX Security 2019 · 21 citations
- ωTest: WebView-Oriented Testing for Android ApplicationsJiajun Hu, Lili Wei, Yepang Liu, Shing-Chi CheungISSTA 2023 · 8 citations
Builds on1
Related papers
- An Empirical Study of Web Resource Manipulation in Real-world Mobile ApplicationsXiaohan Zhang, Yuan Zhang, Qianqian Mo, Hao Xia et al.USENIX Security 2018 · 15 citations
- PhishinWebView: Analysis of Anti-Phishing Entities in Mobile Apps with WebView Targeted PhishingYoonjung Choi, Woonghee Lee, Junbeom HurWWW 2024 · 5 citations
- Tabbed Out: Subverting the Android Custom Tab Security ModelPhilipp Beer, Marco Squarcina, Lorenzo Veronese, Martina LindorferS&P 2024 · 7 citations
- All your app links are belong to us: understanding the threats of instant apps based attacksYutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo et al.FSE 2020 · 22 citations
- Component Security Ten Years Later: An Empirical Study of Cross-Layer Threats in Real-World Mobile ApplicationsKeke Lian, Lei Zhang, Guangliang Yang, Shuo Mao et al.FSE 2024 · 5 citations
