Posts tagged "Security"

3 posts

April 18, 2026
FLAG_MUTABLE PendingIntent in DeviceAsWebcam Allows Foreground Activity Hijack via fillIn() Injection
A mutable notification PendingIntent in DeviceAsWebcam enables fillIn() intent injection and forced foreground launch of a system-UID activity from a NotificationListenerService app.
April 7, 2026
Blocking WiFi De-Auth Attacks in the Kernel with eBPF and XDP
I patched the Linux mac80211 kernel module to support XDP on wireless interfaces and built an eBPF program that detects and drops 802.11 de-authentication floods — reducing detection time by 60% vs libpcap and improving throughput stability over 802.11w. Published at IEEE NetSoft 2025.
April 6, 2026
Intercepting Android's ManagedProvisioning: A PendingIntent Vulnerability in AOSP
I found a vulnerability in Android's ManagedProvisioning that lets any unprivileged app intercept privileged provisioning callbacks. Google classified it as low severity.