frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

TapTrap: Animation‑Driven Tapjacking on Android

https://taptrap.click/
49•Bogdanp•6h ago

Comments

tehwebguy•3h ago
> independently and confidentially reported by @MG193_7 (ByteDance IES RedTeam) to the Android Security Team in early 2023

I wonder if this is in the wild anywhere, it has to be after 2.5 years right?

SoftTalker•3h ago
Another reason not to install random apps.
qbane•2h ago
This has a long history dating back to the Flash era.

https://owasp.org/www-community/attacks/Clickjacking

> One of the most notorious examples of Clickjacking was an attack against the Adobe Flash plugin settings page. By loading this page into an invisible iframe, an attacker could trick a user into altering the security settings of Flash, giving permission for any Flash animation to utilize the computer’s microphone and camera.

user_7832•2h ago
> If you use an Android phone and haven’t disabled system animations, then yes, you’re likely affected. iPhone users are not affected.

Okay... that was much worse than I expected. Looks like you can get the victim to click anywhere, which looks bad. I thought Android had protections against this?

> It is based on transition animations instead of overlays, so it doesn’t need special permissions and isn’t blocked by Android’s overlay protections.

Oh well. Not sure how that slipped past.

altfredd•1h ago
This might be somewhat less threatening then it sounds, because it requires caller to fully control animations used for entering the targeted Activity.

In particular, this vulnerability might not overcome root permission prompts on rooted devices, because their windows are launched and controlled by the installed su app, not by attacker.

Ask HN: Is Tensorflow.js Dead?

1•fouronnes3•1m ago•0 comments

Aging Clock Unveils Compounds That Rejuvenate Brain Cells

https://neurosciencenews.com/aging-clock-neurogenesis-29510/
1•lentoutcry•4m ago•0 comments

Stargate advances with 4.5 GW partnership with Oracle

https://openai.com/index/stargate-advances-with-partnership-with-oracle/
1•taubek•4m ago•0 comments

Show HN: I built a site to help new dog owners pick a boy dog name fast

https://boydognames.net
1•droidHZ•8m ago•0 comments

Capturing anesthetic gases could prevent global warming, new study shows

https://phys.org/news/2025-07-capturing-anesthetic-gases-global.html
2•PaulHoule•13m ago•0 comments

Rescuing two PDP-11s in UK from a former BT underground shelter, central London

https://forum.vcfed.org/index.php?threads/rescuing-two-pdp-11-systems-in-uk-from-a-former-big-british-telecom-underground-shelter-in-central-london.1244723/page-2
2•mhh__•14m ago•0 comments

Extending Emacs with Fennel

https://andreyor.st/posts/2024-12-20-extending-emacs-with-fennel/
2•Bogdanp•22m ago•0 comments

Making Sense of Hanlon's Razor

https://domofutu.substack.com/p/making-sense-of-hanlons-razor
1•wjb3•44m ago•0 comments

Is the Interstellar Object 3I/Atlas Alien Technology?

https://avi-loeb.medium.com/is-the-interstellar-object-3i-atlas-alien-technology-b59ccc17b2e3
2•greesil•46m ago•1 comments

Tamiya chairman Shunsaku Tamiya dies at 90

https://www.dailyexpress.com.my/news/263013/tamiya-chairman-shunsaku-tamiya-dies-at-90/
1•mbrd•54m ago•1 comments

Ask HN: Programmable, affordable developer toys similar to DeskHog?

2•adarshd•57m ago•0 comments

When Is WebAssembly Going to Get DOM Support?

https://queue.acm.org/detail.cfm?id=3746174
2•jazzypants•1h ago•0 comments

Ask HN: What software subscriptions are worth paying for?

20•helloworlddd•1h ago•27 comments

How HN: Vivezia – A Wellness Tracker with Privacy in Mind

https://www.vivezia.com
1•rmagrare•1h ago•0 comments

Private equity firms flip assets to themselves in record numbers

https://www.ft.com/content/88a4e3e3-cefb-48d8-ab81-75cf85039b83
2•cwwc•1h ago•0 comments

Whom Do We Trust? How AI Is (Re)Shaping Our Interactions Today (Gillian Tett) [video]

https://www.youtube.com/watch?v=AVXnBLh9tWY
1•maartenscholl•1h ago•0 comments

Show HN: NextDevKit – Next.js and OpenNext SaaS Template, Goodbye Vercel Bills

https://nextdevkit.com
1•guangzhengli•1h ago•0 comments

The benefits of trunk-based development

https://thinkinglabs.io/articles/2025/07/21/on-the-benefits-of-trunk-based-development.html
25•gpi•1h ago•18 comments

In Ukraine's bombed out reservoir a forest has grown

https://www.theguardian.com/environment/2025/jul/22/in-a-bombed-out-reservoir-ukraine-huge-forest-grown-a-return-to-life-or-toxic-timebomb
5•NewJazz•1h ago•0 comments

Ask HN: Looking for Research Ideas in Cybersecurity (Graduate Student)

1•hogexmox•1h ago•0 comments

Automatic Linux migration tool for windows [video]

https://www.youtube.com/watch?v=PMoXClh8emw
1•Jotalea•1h ago•2 comments

Show HN: Coder.ninja – Best Projects and Coders

https://coder.ninja
1•ethx64•1h ago•0 comments

Photo editing is dead. Long live prompt editing

https://apps.apple.com/tr/app/prompt-pic-prompt-edit-photos/id6747992467
1•flixing•1h ago•0 comments

Italy drags Meta, X, LinkedIn into €1B+ VAT showdown: free sign‑ups now taxable?

https://www.reuters.com/world/europe/meta-x-linkedin-appeal-unprecedented-vat-claim-by-italy-2025-07-21/
6•napolux•1h ago•0 comments

Project Lyra – Exploring Interstellar Objects

https://i4is.org/what-we-do/technical/project-lyra/
2•andsoitis•1h ago•0 comments

Dr. Martin Loetzsch – ETL Patterns with Postgres [video]

https://www.youtube.com/watch?v=whwNi21jAm4
1•banashark•1h ago•0 comments

Fedora Must (Carefully) Embrace Flathub

https://blogs.gnome.org/mcatanzaro/2025/07/21/fedora-must-carefully-embrace-flathub/
2•pabs3•1h ago•0 comments

Microsoft poaches more Google DeepMind AI talent as it beefs up Copilot

https://www.cnbc.com/2025/07/22/microsoft-google-deepmind-ai-talent.html
2•mgh2•2h ago•0 comments

Show HN: PTS Library – Analyze LLM reasoning through "thought anchors"

1•codelion•2h ago•0 comments

Humans beat AI at international math contest despite gold-level AI scores

https://phys.org/news/2025-07-humans-ai-international-math-contest.amp
4•moneil971•2h ago•0 comments