kirancodes.me
To Proof Maintenance & Beyond!

All your app links are belong to us: understanding the threats of instant apps based attacks

Yutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo, Hao Zhou, Zhou Xu

Abstract

Android deep link is a URL that takes users to a specific page of a mobile app, enabling seamless user experience from a webpage to an app. Android app link, a new type of deep link introduced in Android 6.0, is claimed to offer more benefits, such as supporting instant apps and providing more secure verification to protect against hijacking attacks that previous deep links can not. However, we find that the app link is not as secure as claimed, because the verification process can be bypassed by exploiting instant apps.

BibTeX
@inproceedings{Tang-al:FSE20,
  author    = {Yutian Tang and
               Yulei Sui and
               Haoyu Wang and
               Xiapu Luo and
               Hao Zhou and
               Zhou Xu},
  title     = {All your app links are belong to us: understanding the threats of instant apps based attacks},
  booktitle = {{ESEC/SIGSOFT} {FSE}},
  pages     = {914--926},
  publisher = {{ACM}},
  year      = {2020},
}

Related papers