Proceedings 2014 Network and Distributed System Security Symposium 2014
DOI: 10.14722/ndss.2014.23323
|View full text |Cite
|
Sign up to set email alerts
|

Breaking and Fixing Origin-Based Access Control in Hybrid Web/Mobile Application Frameworks

Abstract: Hybrid mobile applications (apps) combine the features of Web applications and "native" mobile apps. Like Web applications, they are implemented in portable, platform-independent languages such as HTML and JavaScript. Like native apps, they have direct access to local device resources -file system, location, camera, contacts, etc.Hybrid apps are typically developed using hybrid application frameworks such as PhoneGap. The purpose of the framework is twofold. First, it provides an embedded Web browser (for exam… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
58
0

Year Published

2016
2016
2020
2020

Publication Types

Select...
5
2
1

Relationship

1
7

Authors

Journals

citations
Cited by 64 publications
(61 citation statements)
references
References 13 publications
0
58
0
Order By: Relevance
“…However, as shown in prior work [19], [26], such a feature also introduces potential security flaws. More specially, it opens a bridge that links web code to^Ğ However, up to now it still remains unclear how adversaries involve the event handler feature in their attack vectors in practice.…”
Section: Introductionmentioning
confidence: 93%
“…However, as shown in prior work [19], [26], such a feature also introduces potential security flaws. More specially, it opens a bridge that links web code to^Ğ However, up to now it still remains unclear how adversaries involve the event handler feature in their attack vectors in practice.…”
Section: Introductionmentioning
confidence: 93%
“…Furthermore, WebView enforces the standard same origin policy [8,42] on the displayed content. An advertising creative displayed in a WebView can interact with the host app through exposed bridge objects [19], but an AdSDK can restrict which bridges are available in its WebViews.…”
Section: Mobile Ad Isolationmentioning
confidence: 99%
“…To limit the typical web application threats, WebViews are re-using the wellknown security mechanism from web browsers such as the same-origin policy [10]. Moreover, WebViews are separated from the regular web browsers on Android, e. g., WebViews have their own cache and cookie store.…”
Section: Security Considerations For Cordova Appsmentioning
confidence: 99%
“…Moreover, WebViews are separated from the regular web browsers on Android, e. g., WebViews have their own cache and cookie store. Still, there are subtle differences that make implementing secure Cordova apps even for experienced web application developers a challenge [9,10].…”
Section: Security Considerations For Cordova Appsmentioning
confidence: 99%
See 1 more Smart Citation