Nullcon Berlin 2023 | Dirty Stream Attack, Turning Android Share Targets To Attack Vectors
About this talk
This talk explores the use of Android intents for information exchange between applications, focusing on how these mechanisms can be exploited through a specific type of vulnerability. The speaker discusses a scenario where a receiving application processes an incoming stream from a malicious app without adequate validation, leading to potential risks such as overwriting critical files or exposing private user data. The session highlights findings from research that identified multiple vulnerable applications on the Google Play Store and emphasizes the importance of implementing security checks to mitigate these risks. The speaker also shares insights on the implications of these vulnerabilities within the context of information security.
More from this event
See all 17 talks →
Nullcon Berlin 2023 | Server Side Prototype Pollution: Blackbox Detection Without The DoS by Gareth
42:10
Nullcon Berlin 2023 | Why I Write My Own Security Tooling & Why You Should Too! by James Forshaw
41:49
Nullcon Berlin 2023 | SCCI: The Road To Side-Channel Regression Testing In CI Development by Witold
46:39
Nullcon Berlin 2023 | Panel: Securing the Road to Autonomy
36:23