Hunting Mobile Tapjacking And Overlay Abuse

Hunt mobile interface redressing, where another app draws over or intercepts a sensitive screen so the user acts on the attacker's terms without knowing it, approving a permission, confirming a transaction, or entering a secret while an overlay hides or fakes what they are really touching, because the sensitive screen does not detect that it is obscured, does not filter touches passed through an overlay, or does not bind the confirmation to what the user actually saw. Use when a mobile app presents consent, confirmation, or credential-entry screens that another app could overlay or intercept. Covers tap hijacking through overlays, obscured-touch acceptance, accessibility-driven interaction, and confirmations not bound to the displayed action. The overlaying or intercepting app is the source, the sensitive screen accepting the redirected interaction is the sink, and the user approving what they did not intend is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-mobile-tapjacking-and-overlay-abuse commit 2e76a3aa7a

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-mobile-tapjacking-and-overlay-abuse