Lune

USENIX Security2026顶会

AutoFail: Breaking Web Boundaries using Android's Autofill Framework

Riccardo Lamarca, Philipp Beer, Marco Squarcina

出版方
2026年份

摘要

Password managers (PWMs) are widely used to improve both usability and security in password-based authentication. On Android, PWMs typically rely on the Autofill Framework (AF) to provide automatic credential filling in native applications and web browsers. The AF acts as an intermediary between apps and PWMs by offering a unified interface for credential extraction and injection. However, web content does not natively match the object structure expected by the AF, which forces browsers to translate a website's Document Object Model (DOM) into an Android-specific representation. This translation step introduces a complex and security-sensitive layer in the autofill pipeline.

In this paper, we present the first systematic security analysis of Android's Autofill Framework pipeline. We introduce ADAPT, a differential-testing based approach that enables an end-to-end inspection of the autofill flow, from the browser's DOM translation process to the PWM's credential matching and filling logic. We identify multiple critical vulnerabilities affecting 9 password managers and 5 widely used mobile browsers. These flaws allow attackers to leak credentials to attacker-controlled origins, bypass web isolation mechanisms, and infer user account relationships across services. We precisely define preconditions for the attacks and evaluate their prevalence in the wild.

We also propose concrete mitigations and a standardized design for secure DOM translation and context-aware credential filling. We disclosed our findings to the affected vendors. Major browser and password manager developers have confirmed our results and are implementing the suggested fixes.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper9

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖