Topic route / 01

Mobile security

Deep links, application boundaries, browser handoffs, and platform behavior that only becomes dangerous when several valid decisions are chained together.

Recommended order

Start here, then go deeper.

Follow the route from verified links into platform metadata, serialized identity, and privileged consumer decisions.

  1. 01
    MobileAndroid App Links: The Link Was Verified. The Action Was Not.

    A field methodology for Android App Links that separates domain ownership, route validation, application state, and server-side authorization before calling a deep link secure.

    18 min ↗
  2. 02
    Android identityCVE-2024-0044: How Installer Metadata Forged an Android App Identity

    A reader-first variant analysis of Android CVE-2024-0044: how a crafted installer name could corrupt packages.list, mislead run-as, and why the first fix needed a follow-up.

    13 min ↗
  3. 03
    Platform CVECVE-2025-24201: How Web Content Reached an Unneeded GPU State

    Read ↗
Full topic archive

Every matching record.

Methods and named-vulnerability research remain visually and editorially separate.