Platform & Code (PC6)
Platform & Code
6
Dawn can expose and intercept sensitive functionality through interprocess communication because permissions for broadcast and sharing are not set, not narrow enough or because sensitive functionality isn't appropriately excluded when sharing
Scenario: Dawn can expose and intercept sensitive functionality through interprocess communication because permissions for broadcast and sharing are not set, not narrow enough or because sensitive functionality isn't appropriately excluded when sharing
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
OWASP MASVS: PLATFORM-1
OWASP MASTG: TEST-0029,TEST-0030,TEST-0071
SAFECode: 8,10,11
Attacks
No attacks registered!