Full Program »
Attacks on WebView in the Android System
The design of WebView changes the landscape of the Web, especially from the security perspective. Two essential pieces of the Web’s security infrastructure are weakened if WebView and its APIs are used: the Trusted Computing Base (TCB) at the client side, and the sandbox protection implemented by browsers. As results, many attacks can be launched either against apps or by them. The objective of this paper is to present these attacks, analyze their fundamental causes, and discuss potential solutions.
Author(s):
Tongbo Luo
Syracuse University
United States
Hao Hao
Syracuse University
United States
Wenliang Du
Syracuse University
United States
Yifei Wang
Syracuse University
United States
Heng Yin
Syracuse University
United States