Analysis The Dangerous Role Of Deep Links by Rahul Kankrale & Yogesh Tantak | Nullcon Berlin 2022
About this talk
This talk examines the use of Android deep links in app development, highlighting both their benefits and potential security vulnerabilities. The speaker discusses how deep links can be exploited by unauthorized applications or websites to access sensitive device features without user consent, particularly focusing on Samsung’s stock Camera app. The vulnerabilities identified allow attackers to capture images, record videos, and access GPS locations without requiring dangerous permissions, posing significant risks to user privacy. The session emphasizes the importance of implementing custom permissions to protect sensitive deep links and prevent exploitation by spyware.
More from this event
See all 19 talks →
Keynote | High-assurance Code Reviews: How Consulting Works When The Risks Are High by Dan Guido
49:15
Night Track | GNU Anastasis: Privacy-Preserving Key Backup And Recovery by Christian Grothoff
28:47
Fuzzware: Automating & Scaling Fuzzing For Firmware by Tobias Scharnowski & Marius Muench | Nullcon
39:10
CXO Panel | Digital Identity In The Age Of Fintech | Nullcon Berlin 2022
56:07