Skip to content
← LibraryTechnique entry
MOB-DEEPLINK-ABUSEInitial Access

Android Deeplink / Intent Abuse

Exported activity / intent-filter with weak validation — craft an intent URL that triggers privileged actions in the app.

§ Where this technique fits

MOB-DEEPLINK-ABUSE is catalogued under the Initial Access tactic of the offensive-security kill-chain. It appears in 2 approved dossiers in the registry, typically at step 3 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01seen 1×
  2. 02
    Intent Injection / Pending Intent Abuse
    MOB-INTENT-INJECT · Privilege Escalation
    seen 1×