WRITEUP · MOBILE · SQL · 2026 · @YNSMROZTAS

Provider selection is SQL

● liveclk --:--:--module · B13

The exported provider took the caller's selection string and glued it into the query. Bind args never saw it.

sqli // liveobserve
radar--:--:--
AndroScopeCWE-89ContentProviderlab only

The trick

Android ContentProvider.query looks like an API. Under it is SQLite. If the implementation concatenates selection or sortOrder into the statement instead of using selectionArgs, every caller who can reach that URI is speaking SQL with the provider's UID.

Lab package lab.sample.app. Authority lab.sample.notes. Exported. No read permission. Contacts-style stores on the platform fail the same way when a helper concatenates instead of binding.

caller query() selection + string glue SQLite fix selectionArgs only. projection allowlist. un-export or perm-gate.
B  APP ATTACK SURFACE
13  Content Provider Probe          ★

session — lab.sample.app
[prov] authority lab.sample.notes · exported
[prov] query() selection concatenated
[prov] selectionArgs unused on that path
[prov] no rows printed on this page

mitsec@lab.sample.app:

What AndroScope is allowed to say

Module 13 on an authorized lab build: authority, exported flag, whether selection is forwarded raw. It does not print table dumps. Empty cursor means you did not hit that URI, not that the glue is safe.

Class: CWE-89 through an exported provider. Same shape as platform contact-store bugs when helpers skip bind args. No tautology kit here.

Fix

YUNUS EMRE ÖZTAŞ · MITSEC · LAB BUILD ONLY