Discovery URL Scheme exists security vulnerabilities _iphone development

Source: Internet
Author: User

Bought subscriptions in an app yesterday (app purchase), when I click to pay Alipay, found that always jump to a "Yunnan mobile" App, tried a few times can not succeed, after thinking about it, should be Alipay URL Scheme was "Yunnan mobile" to register it. So the mobile phone on the "Yunnan mobile" to uninstall, and sure enough Alipay to pay success.
Originally, the URL Scheme for IOS was designed to facilitate the invocation of calls between apps. We can use a OpenURL method to open the specified app and pass some parameters. But Apple does not have any verification of the identity of the App, and the parameters in the URL are transmitted in plaintext, which causes some rogue software to arbitrarily intercept the system to pass to other app URL Scheme calls, such as "Yunnan mobile" app. If these apps are intended to mimic the app on the UI, it's hard for users to know if their information is being abused and leaked by these apps ...

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.