Analyzing Android browser apps for file:// vulnerabilities

Daoyuan WU, Rocky K. C. CHANG

Research output: Book Chapters | Papers in Conference ProceedingsBook ChapterResearchpeer-review

9 Citations (Scopus)

Abstract

Securing browsers in mobile devices is very challenging, because these browser apps usually provide browsing services to other apps in the same device. A malicious app installed in a device can potentially obtain sensitive information through a browser app. In this paper, we identify four types of attacks in Android, collectively known as File- Cross, that exploits the vulnerable file:// to obtain users’ private files, such as cookies, bookmarks, and browsing histories. We design an automated system to dynamically test 115 browser apps collected from Google Play and find that 64 of them are vulnerable to the attacks. Among them are the popular Firefox, Baidu and Maxthon browsers, and the more application-specific ones, including UC Browser HD for tablet users, Wikipedia Browser, and Kids Safe Browser. A detailed analysis of these browsers further shows that 26 browsers (23%) expose their browsing interfaces unintentionally. In response to our reports, the developers concerned promptly patched their browsers by forbidding file:// access to private file zones, disabling JavaScript execution in file:// URLs, or even blocking external file:// URLs. We employ the same system to validate the ten patches received from the developers and find one still failing to block the vulnerability.

Original languageEnglish
Title of host publicationInformation Security: 17th International Conference, ISC 2014, Hong Kong, China, October 12-14, 2014, Proceedings
EditorsSherman S.M. CHOW, Jan CAMENISCH, Lucas C. K. HUI, Siu Ming YIU
PublisherSpringer, Cham
Pages345-363
Number of pages19
ISBN (Electronic)9783319132570
ISBN (Print)9783319132563
DOIs
Publication statusPublished - 20 Nov 2014
Externally publishedYes

Publication series

NameLecture Notes in Computer Science
Volume8783
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Bibliographical note

Publisher Copyright:
© Springer International Publishing Switzerland 2014.

Fingerprint

Dive into the research topics of 'Analyzing Android browser apps for file:// vulnerabilities'. Together they form a unique fingerprint.

Cite this