Precisely and Scalably Vetting JavaScript Bridge in Android Hybrid Apps.

Guangliang Yang,Abner Mendoza,Jialong Zhang,Guofei Gu
DOI: https://doi.org/10.1007/978-3-319-66332-6_7
2017-01-01
Abstract:In this paper, we propose a novel system, named BridgeScope, for precise and scalable vetting of JavaScript Bridge security issues in Android hybrid apps. BridgeScope is flexible and can be leveraged to analyze a diverse set of WebView implementations, such as Android’s default WebView, and Mozilla’s Rhino-based WebView. Furthermore, BridgeScope can automatically generate test exploit code to further confirm any discovered JavaScript Bridge vulnerability.
What problem does this paper attempt to address?