Platform & Code (PCQ)
Platform & Code
Q
Xavier can inject scripts into the web view because it allows embedding content using deep linking without proper authorization and validation of the host, schema and path of the target as these can be changed by the user or because safe browsing is disabled
Scenario: Xavier can inject scripts into the web view because it allows embedding content using deep linking without proper authorization and validation of the host, schema and path of the target as these can be changed by the user or because safe browsing is disabled
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
MASVS: PLATFORM-1,PLATFORM-2
MASTG: TEST-0027,TEST-0028,TEST-0031,TEST-0070,TEST-0076,TEST-0077
CAPEC™: 175,240,242,500,591,592
SAFECode™: 17
No attacks registered!