Главная
Study mode:
on
1
Introduction
2
Chef Sajan
3
India Mohammed
4
Agenda
5
What is a CV
6
Webviews
7
Load URL API
8
Deep Links
9
Conclusion
10
Mobile Application Workflow
11
Bug Explanation
12
Initial Observations
13
Timeline
14
Demo
15
Role of Plan
16
Common Webview Issues
17
Use Case
18
Code snippet
19
Insufficient URL validation
20
Issue with GetHost
21
Impact
22
Unintended Data Leakage
23
Sharing Sensitive Data
24
Lack of Isolation
25
LearningsRecommendations
26
Secure URL Validation
27
Webview Implementation
28
Android Webview Implementation
29
iOS Webview Implementation
30
iOS Webview Settings
31
Learnings
32
References
33
Live Slide
Description:
Explore the intricacies of securing Webviews and uncover the story behind CVE-2021-21136 in this comprehensive conference talk from the Hack In The Box Security Conference. Delve into common Webview-related security issues, including insecure Deeplink implementation, insufficient URL validation, and lack of Webview isolation. Learn prevention techniques to enhance mobile application security and robustness. Discover the journey behind identifying and reporting the Chromium CVE:2021-21136, which exposed sensitive data leakage in Android Webviews. Gain insights from security experts Imdadullah Mohammed and Shiv Sahni as they share their extensive experience in application security, penetration testing, and secure code reviews. Examine detailed code snippets, demonstrations, and real-world examples to understand the complexities of Webview security and its impact on mobile application development.

Securing Webviews and The Story Behind CVE-2021-21136

Hack In The Box Security Conference
Add to list
0:00 / 0:00