
CVE-2020-0096-StrandHogg2 复现
This design flaw allows an attacker to display their own activity (page) on top of another application, potentially causing users to lose track of their private data. This vulnerability is called StrandHogg 2.0 and was recently disclosed by the Norwegian security company Promon.
Scope: Theoretically all versions Android 10 test failed, Android 8.0.1 test succeeded
Verification steps: Modify the code to the target app's package name and exported activity Launch the target app's target activity Launch the test app When launching the target app, the hijacking is successful
https://source.android.com/security/bulletin/2020-05-01
https://github.com/liuyun201990/StrandHogg2/
https://www.xda-developers.com/strandhogg-2-0-android-vulnerability-explained-developer-mitigation/
Android 9.0 and other systems have StrandHogg 2.0 vulnerability
Strandhogg Vulnerability: The Viking Pirate on Android Systems
https://github.com/BoxFighter/Android-StrandHogg-Vulnerability
Waiting for the patch: Operating system vulnerability StrandHogg 2.0 affects almost all Android devices
StrandHogg 2.0 Android vulnerability affects over 1 billion devices
CVE-2020-0096 StrandHogg 2.0 vulnerability analysis