Cruel Intentions: A Security Analysis of Web Intents

Provided by: Carnegie Mellon University
Topic: Software
Format: PDF
Web intents are a new web collaboration framework intended to bring the benefits of Android's Intent model to the web. Web Intents are currently implemented as a JavaScript shim, supporting several major local storage enabled browsers. A prototype native implementation is under development for Google Chrome. While Android's intent model has previously been the subject of significant security review, web intents has not yet received similar scrutiny. In this paper, the authors present several attacks on the prototype implementations of web Intents. They have communicated their recommendations on mitigating these attacks to the web intents developers.

Find By Topic