
DEF CON 33 - Bypassing Intent Destination Checks, LaunchAnyWhere Privilege Escalation - Qidan He
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 46:30
The talk presents a new Android security vulnerability called "bad resolve" that enables "Launch Anywhere" privilege escalation attacks by exploiting race conditions in the intent resolution process 0:10.
Key Takeaways:
• Intents are the core IPC mechanism in Android, allowing applications to communicate with each other, with security restrictions to prevent unauthorized access to protected components 1:56.
• Historical "Launch Anywhere" vulnerabilities allowed attackers to bypass security checks through intent redirection, initially fixed in Android settings but later bypassed through Parcelable serialization mismatches 6:56.
• The "bad resolve" vulnerability exploits a race condition during intent resolution where the system server and settings application resolve the same intent to different targets during a critical time window 14:11.
• Attackers can extend this brief 1-millisecond window by declaring malformed intent filters with thousands of categories, slowing resolution to 100-400 milliseconds and enabling the race condition 24:26.
• Real-world exploits demonstrated include unauthorized phone calls and accessing protected settings activities, with particular effectiveness on certain Android vendor implementations like Xiaomi, Honor, and Huawei devices 38:07.
These vulnerabilities were responsibly disclosed to Google and demonstrate how Android's complex intent resolution system can be exploited through carefully timed race conditions.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Okay. Uh hello everyone and I think this is the time for my talk and it's now uh half past 1 and uh welcome to my talk on the Android security uh which I believe maybe is the only topic at this year's defcon on Android security. So the uh topic of my topic is uh uh Dan made the topic of my talk is Danm made alive again by passing intent destination checks and introducing launch anywhere privilege escalations. So a brief introduction about myself. I'm currently the center director and the chief security researcher at gd.com. I'm leading the dawn security lab and uh which many our lab mainly doing like anti- fraud, client security, security research etc. and I'm previously a winner of the pontoon and mobile ponton competitions and the 2022 pony awards best privilege escalations and um also s…