Android Intent redirection

Redirection through a user-supplied Intent

Description

Passing an Intent object or component information from an external Intent to startActivity, startService, or sendBroadcast without validation can let an attacker use the app's privileges and trust boundaries to launch unintended components.

Potential impact

  • Calls to internal components or permission bypass.
  • Disclosure of sensitive extra values.
  • Phishing screens or malicious components being launched.

Remediation

  1. Do not forward an externally supplied Intent unchanged.
  2. Validate the target package, class, and action against an allow-list.
  3. Use setPackage, setClassName, or setComponent to specify an explicit, trusted destination.

Examples

Before

java
Intent next = getIntent().getParcelableExtra("next");
startActivity(next);

After

java
String target = getIntent().getStringExtra("target");
if ("safe".equals(target)) {
    Intent next = new Intent(this, SafeActivity.class);
    startActivity(next);
}

Explanation:

  • Before: Forwarding an external Intent without validation can let an attacker launch internal or other apps' components with this app's privileges.
  • After: The app creates a new Intent and sets only an approved destination instead of forwarding the external Intent.

References