Hardening the OAuth-WebView Implementations in Android Applications by Re-Factoring the Chromium Library
Fadi Mohsen, Mohamed Elemam Shehab · 2016
Today, the Open Standard for Authorization (OAuth) is widely used by many service providers such as Google, Github, and Facebook. The OAuth-WebView implementation is the most widely used approach despite explicit warnings to the developers of its security and privacy risks. Previous researches have discussed these risks and proposed solutions that mandate numerous implementation's changes and/or do not assume strong attacking assumptions. In this work, we introduce SecureOAuth, a whitelist access control protection framework for the Android platform. SecureOAuth is composed of: Android library modifications, service creation, and system app creation. We have implemented a prototype of the SecureOAuth framework and evaluated it on performance and memory overhead. We also showcase examples of security threats that this framework counters. The framework hardens the OAuth-WebView implementation with bounded overhead while keeping the user's involvement to minimum. Moreover, the framework requires no implementations' changes and it assumes attackers with advanced and expert skill levels.