Proceedings of the 27th Annual Computer Security Applications Conference 2011
DOI: 10.1145/2076732.2076781
|View full text |Cite
|
Sign up to set email alerts
|

Attacks on WebView in the Android system

Abstract: WebView is an essential component in both Android and iOS platforms, enabling smartphone and tablet apps to embed a simple but powerful browser inside them. To achieve a better interaction between apps and their embedded "browsers", WebView provides a number of APIs, allowing code in apps to invoke and be invoked by the JavaScript code within the web pages, intercept their events, and modify those events. Using these features, apps can become customized "browsers" for their intended web applications. Currently… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

2
112
0
1

Year Published

2012
2012
2020
2020

Publication Types

Select...
6
3

Relationship

2
7

Authors

Journals

citations
Cited by 146 publications
(118 citation statements)
references
References 17 publications
2
112
0
1
Order By: Relevance
“…T. Luo, H. Hao, W. Du, Y. Wang and H. Yin in the paper 'Attacks on WebView in Android System' discussed a number of attacks on WebView, either by malicious apps or against non-malicious apps. They identified two fundamental causes of the attacks: weakening of the TCB and Sandbox 10 . A.D. Schmidt and S. Albayrak presented a paper on 'Malicious Software for Smartphones' and presented a list of most common behavior patterns and investigated the possibilities to exploit the standard Symbain OS API and additional malware functionalities 11 .…”
Section: Issues In the Security Of Androidmentioning
confidence: 99%
See 1 more Smart Citation
“…T. Luo, H. Hao, W. Du, Y. Wang and H. Yin in the paper 'Attacks on WebView in Android System' discussed a number of attacks on WebView, either by malicious apps or against non-malicious apps. They identified two fundamental causes of the attacks: weakening of the TCB and Sandbox 10 . A.D. Schmidt and S. Albayrak presented a paper on 'Malicious Software for Smartphones' and presented a list of most common behavior patterns and investigated the possibilities to exploit the standard Symbain OS API and additional malware functionalities 11 .…”
Section: Issues In the Security Of Androidmentioning
confidence: 99%
“…It has already spread through the masses and has affected millions of devices. Currently, they are developing a method to secure the WebView 10 . It is found out that a lot of developers fail to take necessary security precautions.…”
Section: Issues In the Security Of Androidmentioning
confidence: 99%
“…The problems with the addJavascriptInterface in WebView were initially identified by Luo et al [41]. Another work mainly focuses on how the exposed JavaScript interface is used in ads library and their privacy concerns [51].…”
Section: Security Concerns Of Webviewmentioning
confidence: 99%
“…Several vulnerabilities have been identified on Android system and applications in recent years. Luo et al [43] demonstrated attacks on the communication channel between the app and its embedded WebView component. Recently, Wang et al [48] identified unauthorized origin crossing attacks on popular Android apps.…”
Section: Android System Securitymentioning
confidence: 99%