Measuring the Insecurity of Mobile Deep Links of Android
Fang Liu, Chun Wang, Andres Pico, Danfeng Yao, Gang Wang
摘要
Mobile deep links are URIs that point to specific locations within apps, which are instrumental to web-to-app communications. Existing "scheme URLs" are known to have hijacking vulnerabilities where one app can freely register another app's schemes to hijack the communication. Recently, Android introduced two new methods "App links" and "Intent URLs" which were designed with security features, to replace scheme URLs. While the new mechanisms are secure in theory, little is known about how effective they are in practice. In this paper, we conduct the first empirical measurement on various mobile deep links across apps and websites. Our analysis is based on the deep links extracted from two snapshots of 160,000+ top Android apps from Google Play (2014 and 2016), and 1 million webpages from Alexa top domains. We find that the new linking methods (particularly App links) not only failed to deliver the security benefits as designed, but significantly worsen the situation. First, App links apply link verification to prevent hijacking. However, only 194 apps (2.2% out of 8,878 apps with App links) can pass the verification due to incorrect (or no) implementations. Second, we identify a new vulnerability in App link's preference setting, which allows a malicious app to intercept arbitrary HTTPS URLs in the browser without raising any alerts. Third, we identify more hijacking cases on App links than existing scheme URLs among both apps and websites. Many of them are targeting popular sites such as online social networks. Finally, Intent URLs have little impact in mitigating hijacking risks due to a low adoption rate on the web.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- All your app links are belong to us: understanding the threats of instant apps based attacksYutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo 等FSE 2020 · 被引用 22 次
- Automatic Discovery of Emerging Browser Fingerprinting TechniquesJunhua Su, Alexandros KapravelosWWW 2023 · 被引用 17 次
- Component Security Ten Years Later: An Empirical Study of Cross-Layer Threats in Real-World Mobile ApplicationsKeke Lian, Lei Zhang, Guangliang Yang, Shuo Mao 等FSE 2024 · 被引用 5 次
- ReACt: A Resource-centric Access Control System for Web-app Interactions on AndroidXin Zhang, Yifan ZhangWWW 2021 · 被引用 3 次
- SoK: History Doesn't Repeat Itself, but Android Design-Level Vulnerabilities Rhyme in OpenHarmonyHongkai Chen, Yuqing Yang, Chao Wang, Arpit Nandi 等USENIX Security 2026
它引用的顶会 Paper1
相关 Paper
- Vulnerable Implicit Service: A RevisitLingguang Lei, Yi He, Kun Sun, Jiwu Jing 等CCS 2017 · 被引用 5 次
- DeepExploitor: LLM-Enhanced Automated Exploitation of DeepLink Attack in Hybrid AppsZhangyue Zhang, Lei Zhang, Zhibo Zhang, Yongheng Liu 等ASE 2025
- Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS GalaxySajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan 等USENIX Security 2024 · 被引用 7 次
- Towards HTTPS Everywhere on Android: We Are Not There YetAndrea Possemato, Yanick FratantonioUSENIX Security 2020
- Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViewsTongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen 等CCS 2017 · 被引用 47 次
