what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

DropBox iOS / Android App File Theft

DropBox iOS / Android App File Theft
Posted Oct 20, 2012
Authored by Roi Saltzman

DropBox version 1.4.6 on iOS, 2.0.1 on Android, and Google Drive version 1.0.1 on iOS suffer from a file theft vulnerability due to allowing arbitrary javascript to be executed inside of the privileged file zone.

tags | advisory, arbitrary, javascript
systems | apple
SHA-256 | 1100900c25b938d98c9dde4e251799a63bd5241f918b5ca23fa9c84977c34291

DropBox iOS / Android App File Theft

Change Mirror Download
1 Introduction
Recently, I discovered a security vulnerability in several file-sharing apps:
DropBox iOS app, DropBox Android app and Google Drive iOS app.

Exploiting this vulnerability, an attacker could steal arbitrary files
from a DropBox / Google Drive user by tricking him into viewing a malicious
HTML file inside the mobile app.

The full blog post, including the advisories, can be found at:

2 Vulnerability
A significant feature of file-sharing apps is allowing a user to view either
his files or files shared with him. The apps achieve this by using an embedded
browser (using the UIWebView/WebView classes in iOS/Android respectively)
to display the contents of these files. Amongst numerous file types,
these apps allow the user to view HTML files in a rendered format.
To do so, these apps use an embedded browser window to render the
locally stored HTML file.

The method in which these apps render an HTML file has two side effects:
1. JavaScript code contained in the HTML file is automatically executed
2. The HTML content is loaded in a privileged file zone

Execution of malicious JavaScript code allows an attacker to steal potentially
valuable information from the DOM of the embedded browser, an attack dubbed
"Cross-Application Scripting" (XAS). However, because these apps load the HTML
file from a privileged zone such as
(in iOS), the malicious JavaScript can also access the file system with the
same permissions as the app.

3 Impact
By exploiting this vulnerability, an attacker could read and retrieve files
that the apps themselves can access. For instance, previously cached files,
application configuration files, the device's address book, etc.
Furthermore, additional access can be achieved pending on the OS:

- In iOS, read access to the user's DropBox unencrypted credentials
(../Library/Preferences/com.getdropbox.Dropbox.plist). Having access to
the user's credentials allows the attacker to retrieve arbitrary files from
the user's account as well as to persist the attack by modifying other
HTML files.

- In Android, read access to the device's SD card is possible if the app
has permission to do so.

Once the HTML file is rendered, the JavaScript code executes immediately.
However, when the user has finished viewing the file (e.g. pressed the
Home button),
code execution is suspended until the user views the file again.

4 Vulnerable versions
- Version 1.4.6 (iOS)
- Version 2.0.1 (Android)
Google Drive:
- Version 1.0.1 (iOS)

5 Credit
Discovered by Roi Saltzman <roisaltzman () [google's mail server] com>

6 Acknowledgments
I'd like to thank the DropBox / Google security response teams for
the quick fixes!
Login or Register to add favorites

File Archive:

February 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    16 Files
  • 2
    Feb 2nd
    19 Files
  • 3
    Feb 3rd
    0 Files
  • 4
    Feb 4th
    0 Files
  • 5
    Feb 5th
    24 Files
  • 6
    Feb 6th
    2 Files
  • 7
    Feb 7th
    10 Files
  • 8
    Feb 8th
    25 Files
  • 9
    Feb 9th
    37 Files
  • 10
    Feb 10th
    0 Files
  • 11
    Feb 11th
    0 Files
  • 12
    Feb 12th
    17 Files
  • 13
    Feb 13th
    20 Files
  • 14
    Feb 14th
    25 Files
  • 15
    Feb 15th
    15 Files
  • 16
    Feb 16th
    6 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    35 Files
  • 20
    Feb 20th
    25 Files
  • 21
    Feb 21st
    18 Files
  • 22
    Feb 22nd
    15 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files
  • 29
    Feb 29th
    0 Files

Top Authors In Last 30 Days

File Tags


packet storm

© 2022 Packet Storm. All rights reserved.

Security Services
Hosting By