YoVDO

SystemUI as EvilPiP - Hijacking Attacks on Modern Mobile Devices

Offered By: Black Hat via YouTube

Tags

Mobile Security Courses Side Channel Attacks Courses Exploit Development Courses Privilege Escalation Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore a groundbreaking 33-minute Black Hat conference talk unveiling "EvilPiP," a novel hijacking attack on modern Android devices. Delve into the discovery of a new attack surface called PiP, buried in the system for six years, and security issues in privilege processes dating back to 2009. Learn how this research extends beyond traditional Activity Hijack Attacks (AHA) by analyzing framework components, execution chains, and asynchronous rendering processes. Understand how EvilPiP bypasses seven years of hijacking defenses, requires no permissions, and achieves true persistence. Witness a demonstration of this zero-cost, user-unaware attack on high-version Android devices, including API 33 and 34. Gain insights into 10 discovered vulnerabilities, their exploitation, and the ongoing efforts to address these critical mobile security issues.

Syllabus

SystemUI As EvilPiP: The Hijacking Attacks on Modern Mobile Devices


Taught by

Black Hat

Related Courses

Enterprise and Infrastructure Security
New York University (NYU) via Coursera
Palo Alto Networks Cybersecurity Essentials II
Palo Alto Networks via Coursera
Hacking Laboratuvarınızı Oluşturun
Udemy
CISM Cert Prep: 3 Information Security Program Development and Management
LinkedIn Learning
Ethical Hacking: Mobile Devices and Platforms
LinkedIn Learning