Platform & Code (PC5)
Platform & Code
5
Toby can modify or expose data because intents are implicit, contains security-relevant data which apps can register for, or because the response from the intents is not properly validated or sanitized
Scenario: Toby can modify or expose data because intents are implicit, contains security-relevant data which apps can register for, or because the response from the intents is not properly validated or sanitized
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
STRIDE: -
SAFECode™: 17
MASVS: MASVS-PLATFORM-1,MASVS-STORAGE-2,MASVS-CODE-4
No attacks registered!