美文网首页
android deserialization vulnerab

android deserialization vulnerab

作者: 413x | 来源:发表于2018-11-06 17:44 被阅读0次

android deserialization vulnerabilities

this blog is about history

first one

research done by Jann Horn back in 2014. Horn showed that Android allowed deserialization of any class, even non-Java serializable ones, in the context of the attacked app or service leading to remote code execution.

IBM xfore application security research team

that IBM’s X-Force Application Security Research Team found in the Android platform. In a nutshell, advanced attackers could exploit this arbitrary code execution vulnerability to give a malicious app with no privileges the ability to become a “super app” and help the cybercriminals own the device.

相关文章

网友评论

      本文标题:android deserialization vulnerab

      本文链接:https://www.haomeiwen.com/subject/tyouxqtx.html