Improving the security of Android inter-component communication
Adam M. Cozzette, Kathryn Lingel, Steve Matsumoto, Oliver Ortlieb, Jandria Alexander, Joseph Betser, Luke Florer, Geoff Kuenning, John Nilles, Peter L. Reiher · 2013
Abstract—In the Android operating system, each application consists of a set of components that communicate with each other via messages called Intents. The current implementation of Intent handling is such that developers can inadvertently write insecure code that allows malicious applications to intercept or inject Intents to steal sensitive information or induce undesired behavior. We prevented these exploits by modifying Android’s Intent handling behavior to err on the side of safety except where the developer seems to explicitly specify otherwise. Additonally, we confirmed the pervasiveness of Intent vulnerabilities by analyzing the 497 most popular free applications in Android’s official application market, and proved the effectiveness of our modifications by manually verifying that they closed a substantial number of the security holes we identified. I.