Mobile Deeplink Abuse

Abuse deep links / custom URL schemes / intents for redirect, token theft, and reaching internal screens. Load on custom schemes (myapp://), App Links/Universal Links, exported activities, or "open in app". Signals: intent-filters in the manifest, WebView loading deep-link params, OAuth redirect via a custom scheme.

NoorQureshi Updated

File contents

NoorQureshi/SploitAgent/tree/main/skills/mobile/mobile-deeplink-abuse commit 4b8645fa00

Frequently asked questions

npx skillmds@latest add noorqureshi/mobile-deeplink-abuse