Paypal Android App Remote Code Execution
labs.mwrinfosecurity.com
labs.mwrinfosecurity.com
Maybe its because I haven't properly had coffee yet or because I've never used WebView in android but I'm having trouble parsing this. From the small code snippet they provided it shows them enabling javascript and adding an interface. Is this just a general comment for other apps that are working on HTTP or broken HTTPS or does it relate to this exploit?
If the app then uses HTTP or HTTPS without certificate validation, it is easily possible to inject JavaScrpipt code even when no Cross-Site Scripting vulnerability exists in the app.
[1] https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-66...
[2] https://labs.mwrinfosecurity.com/advisories/2013/09/24/webvi...
Wow, good job PayPal.
That does not sound good.
Weird enough no funds from my account disappeared. Not sure if me acting so far(within minutes of compromise) had to do with it.