AutoFail: Breaking Web Boundaries using Android's Autofill Framework
Riccardo Lamarca, Philipp Beer, Marco Squarcina
摘要
Password managers (PWMs) are widely used to improve both usability and security in password-based authentication. On Android, PWMs typically rely on the Autofill Framework (AF) to provide automatic credential filling in native applications and web browsers. The AF acts as an intermediary between apps and PWMs by offering a unified interface for credential extraction and injection. However, web content does not natively match the object structure expected by the AF, which forces browsers to translate a website's Document Object Model (DOM) into an Android-specific representation. This translation step introduces a complex and security-sensitive layer in the autofill pipeline.
In this paper, we present the first systematic security analysis of Android's Autofill Framework pipeline. We introduce ADAPT, a differential-testing based approach that enables an end-to-end inspection of the autofill flow, from the browser's DOM translation process to the PWM's credential matching and filling logic. We identify multiple critical vulnerabilities affecting 9 password managers and 5 widely used mobile browsers. These flaws allow attackers to leak credentials to attacker-controlled origins, bypass web isolation mechanisms, and infer user account relationships across services. We precisely define preconditions for the attacks and evaluate their prevalence in the wild.
We also propose concrete mitigations and a standardized design for secure DOM translation and context-aware credential filling. We disclosed our findings to the affected vendors. Major browser and password manager developers have confirmed our results and are implementing the suggested fixes.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski 等NDSS 2019 · 被引用 826 次
- Phishing Attacks on Modern AndroidSimone Aonzo, Alessio Merlo, Giulio Tavella, Yanick FratantonioCCS 2018 · 被引用 68 次
- Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern WebMarco Squarcina, Mauro Tempesta, Lorenzo Veronese, Stefano Calzavara 等USENIX Security 2021 · 被引用 30 次
- Fill in the Blanks: Empirical Analysis of the Privacy Threats of Browser Form AutofillXu Lin, Panagiotis Ilia, Jason PolakisCCS 2020 · 被引用 24 次
- Tabbed Out: Subverting the Android Custom Tab Security ModelPhilipp Beer, Marco Squarcina, Lorenzo Veronese, Martina LindorferS&P 2024 · 被引用 7 次
相关 Paper
- Vault Raider: Stealthy UI-based Attacks Against Password Managers in Desktop EnvironmentsAndrea Infantino, Mir Masood Ali, Kostas Solomos, Jason PolakisNDSS 2026 · 被引用 1 次
- They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and WebsitesNicolas Huaman, Sabrina Amft, Marten Oltrogge, Yasemin Acar 等S&P 2021 · 被引用 37 次
- Passwords and FIDO2 Are Meant To Be Secret: A Practical Secure Authentication Channel for Web BrowsersAnuj Gautam, Tarun Kumar Yadav, Garrett Smith, Kent E. Seamons 等CCS 2025
- Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context VulnerabilitiesGuangliang Yang, Jeff Huang, Guofei GuUSENIX Security 2019 · 被引用 21 次
- Security Analysis of Master-Password-Protected Password Management ProtocolsYihe Duan, Ding Wang, Yanduo FuS&P 2025
