sponsors
usenix conference policies
A View to a Kill: WebView Exploitation
Matthias Neugschwandtner, Martina Lindorfer, and Christian Platzer, Vienna University of Technology
WebView is a technique to mingle web and native applications for mobile devices. The fact that its main incentive requires making data stored on, as well as the functionality of mobile devices, directly accessible to active web content, is not without consequences to security.
In this paper, we present a threat scenario that targets WebView apps and show its practical applicability in a case study of selected apps. We further show results of our examination of over 287,000 apps in regard to WebView-related vulnerabilities.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Matthias Neugschwandtner and Martina Lindorfer and Christian Platzer},
title = {A View to a Kill: {WebView} Exploitation},
booktitle = {6th USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET 13)},
year = {2013},
address = {Washington, D.C.},
url = {https://www.usenix.org/conference/leet13/workshop-program/presentation/neugschwandtner},
publisher = {USENIX Association},
month = aug
}
connect with us