Day[0] cover image

Attack of the CUPS and Exploiting Web Views via HSTS

Day[0]

00:00

Intro

This chapter focuses on security vulnerabilities in Android client web views, specifically utilizing HTTP Strict Transport Security and the HSTS preload list. It details how poor URL validation can be exploited for privilege escalation through a maliciously crafted URL, highlighting technical aspects of custom WebViews and their JavaScript APIs.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app