HTML5-based mobile apps vulnerable to cross-site scripting attacks: Experts

Advertisement
By Indo Asian News Service | Updated: 10 April 2014 13:57 IST
As you are busy sending SMSs, reading emails or listening to music on your smart phone, do you realise that these simple things can get your smart phone infected with 'worms' that can not only steal personal information from your phone, but also infect your friends's phones?

Sound scary? You can blame a new technology that is behind the development of your favourite apps.

An emerging technology called HTML5-based app development has been rapidly gaining popularity in the mobile industry.

"When the adoption of this technology reaches certain threshold, worm attacks would become quite common unless we do something to stop it," a latest report from US-based IT research agency Gartner warned.

Advertisement

By 2016, 50 percent of the mobile apps will be using HTML5-based technologies.

"All major mobile systems would be affected, including Android, iOS, Blackberry, Windows Phone, etc., because they all support HTML5-based mobile apps," the report cautioned.

A notorious problem of the HTML5-based technology is that malicious code can be easily injected into the programme and get executed.

Advertisement

That is why the Cross-Site Scripting (XSS) attack is still one of the most common attacks in the Web.

"XSS attacks can only target at web applications through a single channel (Internet) but with the adoption of the same technology in mobile devices, we have found out that a similar type of attack can not only be launched against mobile apps," Gartner noted.

Advertisement

It can attack from Wi-Fi scanning, Bluetooth pairing, MP3 songs, MP4 videos, SMS messages, NFC tags and contact list.

"As long as an HTML5-based app displays information obtained from outside or from another app, it may be a potential victim," Gartned added.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. World's Biggest Alien Search Enters Final Stage With 100 Mystery Signals
  2. Avatar: Fire and Ash OTT Release: When, Where to Watch the Sci-Fi Fantasy
  3. Shambhala OTT Release: When, Where to Watch the Telugu Supernatural Horror
  4. Gurram Paapi Reddy OTT Release: When, Where to Watch This Telugu Crime Comedy
  5. Top Deals on Gaming Laptops During Amazon Great Republic Day Sale
  1. World’s Biggest Alien Search Enters Final Stage With 100 Mystery Signals
  2. NASA Pulls Out Artemis II Rocket to Launch Pad Ahead of Historic Moon Mission
  3. Shambhala OTT Release: When, Where to Watch the Telugu Supernatural Horror Film
  4. AGS 28 OTT Release: Know Where to Watch This Tamil Entertainer Starring Arjun, Abhirami
  5. Avatar: Fire and Ash OTT Release: When, Where to Watch James Cameron’s Epic Sci-Fi Fantasy
  6. OpenAI to Begin Testing Ads in ChatGPT, Says Responses Will Not Be Influenced
  7. Gurram Paapi Reddy OTT Release: When, Where to Watch This Telugu Crime Comedy Thriller
  8. Hypothetical ‘Dark Stars’ Could Rewrite Early Cosmic History, Research Suggests
  9. Honor Magic 8 Pro Air Key Features Confirmed; Company Teases External Lens for Honor Magic 8 RSR Porsche Design
  10. Lava Blaze Duo 3 India Launch Date Announced; Colour Options Teased Ahead of Debut
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.