← LibraryTechnique entry
MOB-CONTENT-PROVIDERCollection
Content Provider Data Leak
Exported ContentProvider with insufficient grantUri checks — third-party app reads private data (auth tokens, PII, cached creds).
§ Where this technique fits
MOB-CONTENT-PROVIDER is catalogued under the Collection tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 2 on average.
§ Dossiers chaining this technique
§ What commonly comes next
- 01File and Directory Discoveryseen 1×T1083 · Discovery