#NullconBerlin2025 | My Other ClassLoader is Your ClassLoader Reloaded: Reviving Parcelable Objects
About this talk
This talk by Dimitrios Valsamaras delves into the intricacies of Java ClassLoaders and their role in the Android ecosystem, particularly regarding Parcelable objects. The speaker explains how the dynamic loading of classes can be exploited in the context of data transfer, highlighting the security vulnerabilities that arise from trusting serialized objects from untrusted sources. Valsamaras introduces a technique for intercepting and modifying Parcelable objects, demonstrating how attackers can manipulate serialized data with ease. The discussion emphasizes the critical need for improved security practices in Android development to safeguard against these potential exploits.
More from this event
See all 16 talks →
#NullconBerlin2025 | Panel: Industrial Systems In The Crosshairs: What It Really Takes To Defend OT
51:53
#NullconBerlin2025 | Stealing All macOS Sensitive Info with a Single Vulnerability by Koh
29:22
#NullconBerlin2025 | Derandomizing Kernel Object Locations w Software Hardware-Induced Side Channels
37:23
#NullconBerlin2025 | Your MCP Server Executes Commands - But From Whom? by Simcha Kosman
35:03