Android Parcels - The Bad, the Good and the Better - Introducing Android's Safer Parcel
Offered By: Black Hat via YouTube
Course Description
Overview
Explore a comprehensive 39-minute conference talk from Black Hat that delves into Android's Parcel serialization mechanism and its security implications. Gain insights into the vulnerabilities associated with Parcelable implementations, which have plagued Android for nearly a decade. Discover how these high-severity flaws have been exploited by malware authors to achieve privileged exploits, including silent package installation and arbitrary code execution. Learn about various exploit techniques, such as the persistent Bundle FengShui exploits, and a newly reported exploit chain (CVE-2021-0928) that enables arbitrary code execution in privileged application processes on Android 12. Presented by Hao Ke, Bernardo Rufino, Maria Uretsky, and Yang Yang, this talk offers a detailed examination of Android Parcels' security landscape and introduces the concept of a safer Parcel implementation.
Syllabus
Android Parcels: The Bad, the Good and the Better - Introducing Android's Safer Parcel
Taught by
Black Hat
Related Courses
Creative, Serious and Playful Science of Android AppsUniversity of Illinois at Urbana-Champaign via Coursera Pattern-Oriented Software Architectures: Programming Mobile Services for Android Handheld Systems
Vanderbilt University via Coursera Android. Programación de Aplicaciones
MirÃadax Programming Mobile Applications for Android Handheld Systems: Part 1
University of Maryland, College Park via Coursera Begin Programming: Build Your First Mobile Game
University of Reading via FutureLearn