Overview
Syllabus
Intro
Agenda
Who we are
The Pendingintent API
Previous Research
Retrieving Pendingintents
Hijacking Insecure Pendingintents
Deep Dive Into PendingIntent
Hijacking Pendingintents with Implicit Base Intent
Case Studies
POC of CVE-2020-0188
CVE-2020-0389: Notification
A-166126300: MediaBrowser Service
Some High Profile Apps: AppWidgets
CVE-2020-0294: System Service
Restrictions on URI Grant from uid 1000
Hunting Insecure Pendingintents Automatically
Search APIs without IMMUTABLE
Search Empty or Implicit base Intents
Security Changes in Android 12
Security Guidelines
Final Advice
Taught by
Black Hat