During a static analysis of an Android application, you find an exported component with intent-filters handling external URIs but lacking permission attributes. Which vulnerability does this configuration introduce?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- AModifying native libraries is about tampering with the app package itself, and an exported component's manifest settings have nothing to do with native library integrity.
- BAn exported component does not run shell commands by default; the exposure is that other apps can reach it, and any impact depends on what the component does with the input.
- CCorrect: an exported component without a permission requirement can be invoked by any app on the device, so access controls can be bypassed unless the component validates its callers and input.
- DA missing permission attribute does not stop an app from launching; newer Android versions only require exported components with intent filters to declare the exported value explicitly.