Medusa Attack: Exploring Security Hazards of In-App QR Code Scanning
Xing Han, Yuheng Zhang, Xue Zhang, Zeyuan Chen, Mingzhe Wang, Yiwei Zhang, Siqi Ma, Yu Yu, Elisa Bertino, Juanru Li
摘要
Smartphone users are eliminating traditional QR codes as many apps have integrated QR code scanning as a built-in functionality. With the support of embedded QR code scanning components, apps can read QR codes and immediately execute relevant activities, such as boarding a flight. Handling QR codes in such an automated manner is obviously user-friendly. However, this automation also creates an opportunity for attackers to exploit apps through malicious QR codes if the apps fail to properly check these codes. In this paper, we systematize and contextualize attacks on mobile apps that use built-in QR code readers. We label these as MEDUSA attacks, which allow attackers to remotely exploit the in-app QR code scanning of a mobile app. Through a MEDUSA attack, remote attackers can invoke a specific type of app functions -Remotely Accessible Handlers (RAHs), and perform tasks such as sending authentication tokens or making a payment. We conducted an empirical study on 800 very popular Android and iOS apps with billions of users in the two largest mobile ecosystems, the US and mainland China mobile markets, to investigate the prevalence and severity of MEDUSA attack related security vulnerabilities. Based on our proposed vulnerability detection technique, we thoroughly examined the target apps and discovered that a wide range of them are affected. Among the 377/800 apps with in-app QR code scanning functionality, we found 123 apps containing 2,872 custom RAHs that were vulnerable to the MEDUSA attack. By constructing proof-of-concept exploits to test the severity, we confirmed 46 apps with critical or high-severity vulnerabilities, which allows attackers to access sensitive local resources or remotely modify the user data. Listing 11 Sample JavaSrcript Code of DSBridge var dsBridge=require("dsbridge"); var str=dsBridge.call("nativeMethod","arg");
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Misdirection of Trust: Demystifying the Abuse of Dedicated URL Shortening ServiceZhibo Zhang, Lei Zhang, Zhangyue Zhang, Geng Hong 等NDSS 2025
- What You Decode Depends on Where You Stand: Distance-Based Optical QR CodePulkit Garg, Robin Verma, Somitra Sanadhya, Gaurav GuptaUSENIX Security 2026
- Shielding QR Codes: Unveiling the Real-World Illicit Promotion Behind Adversarial QR CodesLijie Wu, Xiaoping Zhang, Mingxuan Liu, Yue Qin 等USENIX Security 2026
- When Authorization Loses Its Meaning: Breaking and Fixing Third-Party Online PaymentsYongkang Xiao, Jing Chen, Min Shi, Kun He 等USENIX Security 2026
- Demystifying the (In)Security of QR Code-based Login in Real-world DeploymentsXin Zhang, Xiaohan Zhang, Bo Zhao, Yuhong Nan 等USENIX Security 2025
它引用的顶会 Paper7
- Automated Generation of Event-Oriented Exploits in Android Hybrid AppsGuangliang Yang, Jeff Huang, Guofei GuNDSS 2018 · 被引用 79 次
- Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViewsTongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen 等CCS 2017 · 被引用 47 次
- Study and Mitigation of Origin Stripping Vulnerabilities in Hybrid-postMessage Enabled Mobile ApplicationsGuangliang Yang, Jeff Huang, Guofei Gu, Abner MendozaS&P 2018 · 被引用 27 次
- Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context VulnerabilitiesGuangliang Yang, Jeff Huang, Guofei GuUSENIX Security 2019 · 被引用 21 次
- Understanding and Mitigating Remote Code Execution Vulnerabilities in Cross-platform EcosystemFeng Xiao, Zheng Yang, Joey Allen, Guangliang Yang 等CCS 2022 · 被引用 14 次
相关 Paper
- Development, Evaluation, and Implementation of SEQR - a Usable Secure QR Code ScannerMattia Mossano, Maxime Fabian Veit, Tobias Länge, Benjamin Maximilian Berens 等CHI 2026 · 被引用 1 次
- Scanned and Scammed: Insecurity by ObsQRity? Measuring User Susceptibility and Awareness of QR Code-Based AttacksMarvin Kowalewski, Leona Lassak, Markus Dürmuth, Theodor SchnitzlerUSENIX Security 2025
- Do You See How I Pose? Using Poses as an Implicit Authentication Factor for QR Code PaymentChuxiong Wu, Qiang ZengUSENIX Security 2024 · 被引用 2 次
- All your app links are belong to us: understanding the threats of instant apps based attacksYutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo 等FSE 2020 · 被引用 22 次
- iOS, Your OS, Everybody's OS: Vetting and Analyzing Network Services of iOS ApplicationsZhushou Tang, Ke Tang, Minhui Xue, Yuan Tian 等USENIX Security 2020
