美文网首页
android deserialization vulnerab

android deserialization vulnerab

作者: 413x | 来源:发表于2018-11-06 17:44 被阅读0次

    android deserialization vulnerabilities

    this blog is about history

    first one

    research done by Jann Horn back in 2014. Horn showed that Android allowed deserialization of any class, even non-Java serializable ones, in the context of the attacked app or service leading to remote code execution.

    IBM xfore application security research team

    that IBM’s X-Force Application Security Research Team found in the Android platform. In a nutshell, advanced attackers could exploit this arbitrary code execution vulnerability to give a malicious app with no privileges the ability to become a “super app” and help the cybercriminals own the device.

    相关文章

      网友评论

          本文标题:android deserialization vulnerab

          本文链接:https://www.haomeiwen.com/subject/tyouxqtx.html