Static Analysis - com.ss.android.ugc.trill · 07/05/2017  · com.ss.android.ugc.trill.apk APP...

78
Static Analysis - com.ss.android.ugc.trill.apk APP SCORE Average CVSS Score: 6.0 App Security Score: 10/100 Trackers Detection: 9/285 FILE INFORMATION File Name: com.ss.android.ugc.trill.apk Size: 35.02MB MD5: 7d38c0b9ff3bf6b4503e75c4e8e7cc08 SHA1: 154dd33d5c09a12e476c89e1c34b964885049073 SHA256: fb0b820b299607a11ccd5ea66257f7ca3b5d04c1cc702da11a7b58bbaa0ffa98 APP INFORMATION App Name: TikTok Package Name: com.ss.android.ugc.trill Main Activity: com.kakao.auth.authorization.authcode.KakaoWebViewActivity Target SDK: 28 Min SDK: 16 Max SDK: Android Version Name: 10.0.9 Android Version Code: 100009 PLAY STORE INFORMATION Title: TikTok Score: None Installs: 100,000,000+ Price: 0 Android Version Support: 4.1 and up Category: Video Players & Editors Play Store URL: Developer Details: TikTok Pte. Ltd., TikTok+Pte.+Ltd., 201 Henderson Road #06-22,

Transcript of Static Analysis - com.ss.android.ugc.trill · 07/05/2017  · com.ss.android.ugc.trill.apk APP...

  • Static Analysis -com.ss.android.ugc.trill.apk

    APP SCORE

    Average CVSS Score: 6.0

    App Security Score: 10/100

    Trackers Detection: 9/285

    FILE INFORMATION

    File Name: com.ss.android.ugc.trill.apk

    Size: 35.02MB

    MD5: 7d38c0b9ff3bf6b4503e75c4e8e7cc08

    SHA1: 154dd33d5c09a12e476c89e1c34b964885049073

    SHA256: fb0b820b299607a11ccd5ea66257f7ca3b5d04c1cc702da11a7b58bbaa0ffa98

    APP INFORMATION

    App Name: TikTok

    Package Name: com.ss.android.ugc.trill

    Main Activity: com.kakao.auth.authorization.authcode.KakaoWebViewActivity

    Target SDK: 28

    Min SDK: 16

    Max SDK:

    Android Version Name: 10.0.9

    Android Version Code: 100009

    PLAY STORE INFORMATION

    Title: TikTok

    Score: None Installs: 100,000,000+ Price: 0 Android Version Support: 4.1 and upCategory: Video Players & Editors Play Store URL:

    Developer Details: TikTok Pte. Ltd., TikTok+Pte.+Ltd., 201 Henderson Road #06-22,

    https://play.google.com/store/apps/details?id=com.ss.android.ugc.trill&hl=en&gl=us

  • Apex@Henderson Singapore, SGP, https://www.tiktok.com/, [email protected],

    Release Date: May 7, 2017 Privacy Policy: Privacy link

    Description:

    TikTok is a global video community powered by music. Whether it’s dance, free-style or performance, creators are encouraged to let their imagination run wild and set their expressions free. Designed for the global creators, TikTok allows users to quickly and easily create unique short videos to share with friends and the world. TikTok is the new cultural benchmark for global creators. We strive to empower more creative minds to be part of the content revolution.

    [Facial Recognition]High-speed image capture and perfect facial feature matching for all your cute, cool, silly, goofy and outrageous expression.

    [Crisp Quality]Load instantly, smooth interface, and lag free. Every detail displayed in perfect quality. Your eyes will thank you and your mom will love you.

    [Mobile Studio]The perfect marriage between artificial intelligence and image capturing. Enhancing product offering through rhythm synchronization, special effects, and advanced technology. Turn your phone into a full-blown creative studio.

    [Massive Music Library]A sea of music library with fresh editor's pick daily. Take your creative potential to the next level and unlock the world of endless possibilities.

    [Gaga Dance]Gaga Dance launched! Start a Gaga Dance competition with your friends!How many points you can dance?

    SIGNER CERTIFICATE

    APK is signedv1 signature: Truev2 signature: Truev3 signature: FalseFound 1 unique certificatesSubject: C=CN, ST=Beijing, L=Beijing, O=ByteDance, OU=ByteDance, CN=Micro CaoSignature Algorithm: rsassa_pkcs1v15Valid From: 2011-12-31 08:35:54+00:00Valid To: 2039-05-18 08:35:54+00:00Issuer: C=CN, ST=Beijing, L=Beijing, O=ByteDance, OU=ByteDance, CN=Micro CaoSerial Number: 0x4efec96aHash Algorithm: sha1md5: aea615ab910015038f73c47e45d21466sha1: 00a584e375b5573c89e1f06f5cf60d0d65ddb632sha256: d7811ec4166fea6cc720ba66699dc84b584ac9e6986613a76d4e43d8cbe32b27sha512: 2cca66bc77bd61f50c7692426e62d024833cdb03dc67ffacdfd5184eb0596c3ed5acbf71b53da7c5e712a43603c9e42fb3cab9db676532d969a907e7afbc40fePublicKey Algorithm: rsaBit Size: 2048Fingerprint: 766b77a1b76a673957a171efce08352d420f9c595ec35ad68ea75ecc7f725d2f

    Certificate Status: BadDescription:The app is signed with SHA1withRSA. SHA1 hash algorithm is known tohave collision issues.

    PERMISSIONS

    PERMISSION STATUS INFO DESCRIPTION

    https://www.tiktok.com/i18n/privacy/

  • android.permission.ACCESS_FINE_LOCATION dangerous fine (GPS) location

    Access fine location sources, such as the GlobalPositioning System on the phone, where available.Malicious applications can use this to determine whereyou are and may consume additional battery power.

    android.permission.ACCESS_COARSE_LOCATION dangerous coarse (network-based) location

    Access coarse location sources, such as the mobilenetwork database, to determine an approximate phonelocation, where available. Malicious applications can usethis to determine approximately where you are.

    android.permission.INTERNET dangerous full Internetaccess Allows an application to create network sockets.

    android.permission.READ_PHONE_STATE dangerous read phone stateand identity

    Allows the application to access the phone features ofthe device. An application with this permission candetermine the phone number and serial number of thisphone, whether a call is active, the number that call isconnected to and so on.

    android.permission.ACCESS_NETWORK_STATE normal view networkstatus Allows an application to view the status of all networks.

    android.permission.READ_EXTERNAL_STORAGE dangerous read SD cardcontents Allows an application to read from SD Card.

    android.permission.WRITE_EXTERNAL_STORAGE dangerous read/modify/deleteSD card contents Allows an application to write to the SD card.

    android.permission.ACCESS_WIFI_STATE normal view W i-Fi status Allows an application to view the information about thestatus of W i-Fi.

    android.permission.CAMERA dangerous take pictures andvideos

    Allows application to take pictures and videos with thecamera. This allows the application to collect imagesthat the camera is seeing at any time.

    android.permission.RECORD_AUDIO dangerous record audio Allows application to access the audio record path.android.permission.FLASHLIGHT normal control flashlight Allows the application to control the flashlight.

    android.permission.WAKE_LOCK dangerous prevent phonefrom sleepingAllows an application to prevent the phone from goingto sleep.

    android.permission.GET_TASKS dangerous retrieve runningapplications

    Allows application to retrieve information aboutcurrently and recently running tasks. May allowmalicious applications to discover private informationabout other applications.

    android.permission.READ_CONTACTS dangerous read contact data

    Allows an application to read all of the contact(address) data stored on your phone. Maliciousapplications can use this to send your data to otherpeople.

    android.permission.RECEIVE_BOOT_COMPLETED normal automatically startat boot

    Allows an application to start itself as soon as thesystem has finished booting. This can make it takelonger to start the phone and allow the application toslow down the overall phone by always running.

    android.permission.VIBRATE normal control vibrator Allows the application to control the vibrator.com.meizu.c2dm.permission.RECEIVE signature C2DM permissions Permission for cloud to device messaging.

    com.ss.android.ugc.trill.permission.READ_ACCOUNT dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.ss.android.ugc.trill.permission.WRITE_ACCOUNT dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.android.launcher.permission.INSTALL_SHORTCUT normal Allows an application to install a shortcut in Launcher.

    com.android.launcher.permission.UNINSTALL_SHORTCUT normal Don't use this permission in your app. This permissionis no longer supported.

    com.android.launcher.permission.READ_SETTINGS dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    android.permission.AUTHENTICATE_ACCOUNTS dangerous act as an accountauthenticator

    Allows an application to use the account authenticatorcapabilities of the Account Manager, including creatingaccounts as well as obtaining and setting theirpasswords.

    com.htc.launcher.permission.READ_SETTINGS dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.lge.launcher.permission.READ_SETTINGS dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.lge.launcher.permission.WRITE_SETTINGS dangerous modify globalsystem settings

    Allows an application to modify the system's settingsdata. Malicious applications can corrupt your system'sconfiguration.

    com.huawei.launcher3.permission.READ_SETTINGS dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.huawei.launcher3.permission.WRITE_SETTINGS dangerous modify globalsystem settings

    Allows an application to modify the system's settingsdata. Malicious applications can corrupt your system'sconfiguration.

    com.huawei.launcher2.permission.READ_SETTINGS dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.huawei.launcher2.permission.WRITE_SETTINGS dangerous modify globalsystem settings

    Allows an application to modify the system's settingsdata. Malicious applications can corrupt your system'sconfiguration.

    com.ebproductions.android.launcher.permission.READ_SETTINGS dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.ebproductions.android.launcher.permission.WRITE_SETTINGS dangerous modify globalsystem settings

    Allows an application to modify the system's settingsdata. Malicious applications can corrupt your system'sconfiguration.

    com.oppo.launcher.permission.READ_SETTINGS dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.oppo.launcher.permission.WRITE_SETTINGS dangerous modify globalsystem settings

    Allows an application to modify the system's settingsdata. Malicious applications can corrupt your system'sconfiguration.

    com.huawei.android.launcher.permission.READ_SETTINGS dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.huawei.android.launcher.permission.WRITE_SETTINGS dangerous modify globalsystem settings

    Allows an application to modify the system's settingsdata. Malicious applications can corrupt your system'sconfiguration.

    dianxin.permission.ACCESS_LAUNCHER_DATA dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    PERMISSION STATUS INFO DESCRIPTION

  • com.miui.mihome2.permission.READ_SETTINGS dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.miui.mihome2.permission.WRITE_SETTINGS dangerous modify globalsystem settings

    Allows an application to modify the system's settingsdata. Malicious applications can corrupt your system'sconfiguration.

    android.permission.FOREGROUND_SERVICE normal Allows a regular application to useService.startForeground

    com.ss.android.ugc.trill.permission.MIPUSH_RECEIVE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.ss.android.ugc.trill.push.permission.MESSAGE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.meizu.flyme.push.permission.RECEIVE signature C2DM permissions Permission for cloud to device messaging.

    android.permission.WRITE_SYNC_SETTINGS dangerous write sync settings Allows an application to modify the sync settings, suchas whether sync is enabled for Contacts.

    com.sec.android.provider.badge.permission.READ dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.sec.android.provider.badge.permission.WRITE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.htc.launcher.permission.UPDATE_SHORTCUT dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.sonyericsson.home.permission.BROADCAST_BADGE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.sonymobile.home.permission.PROVIDER_INSERT_BADGE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.majeur.launcher.permission.UPDATE_BADGE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.huawei.android.launcher.permission.CHANGE_BADGE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.android.vending.BILLING dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    android.permission.MODIFY_AUDIO_SETTINGS dangerous change your audiosettingsAllows application to modify global audio settings, suchas volume and routing.

    android.permission.EXPAND_STATUS_BAR normal expand/collapsestatus bar Allows application to expand or collapse the status bar.

    android.permission.REQUEST_INSTALL_PACKAGES dangerous

    Allows anapplication torequest installingpackages.

    Malicious applications can use this to try and trick usersinto installing additional malicious packages.

    android.permission.REORDER_TASKS dangerousreorderapplicationsrunning

    Allows an application to move tasks to the foregroundand background. Malicious applications can forcethemselves to the front without your control.

    com.ss.android.ugc.trill.miniapp.PROCESS_COMMUNICATION dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.google.android.finsky.permission.BIND_GET_INSTALL_REFERRER_SERVICE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.google.android.c2dm.permission.RECEIVE signature C2DM permissions Permission for cloud to device messaging.

    android.permission.READ_APP_BADGE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    me.everything.badger.permission.BADGE_COUNT_READ dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    me.everything.badger.permission.BADGE_COUNT_WRITE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    android.permission.UPDATE_APP_BADGE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.vivo.notification.permission.BADGE_ICON dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.ss.android.ugc.trill.permission.RECEIVE_ADM_MESSAGE dangerousUnknownpermission fromandroid reference

    Unknown permission from android reference

    com.amazon.device.messaging.permission.RECEIVE signature C2DM permissions Permission for cloud to device messaging.

    android.permission.USE_CREDENTIALS dangerous

    use theauthenticationcredentials of anaccount

    Allows an application to request authentication tokens.

    android.permission.MANAGE_ACCOUNTS dangerous manage theaccounts listAllows an application to perform operations like addingand removing accounts and deleting their password.

    PERMISSION STATUS INFO DESCRIPTION

    ANDROID LIBRARY BINARY ANALYSIS

    ISSUE SEVERITY DESCRIPTION FILESNo issue found info

    APKiD ANALYSIS

  • APKiD not enabled.

    FILE

    BROWSABLE ACTIVITIES

    ACTIVITY INTENTnet.openid.appauth.RedirectUriReceiverActivity Schemes: com.googleusercontent.apps.1096011445005-qqsj3hcu9s53dv6pbdrl6vs8ls649v01://,

    com.ss.android.ugc.aweme.app.AppLinkHandler

    Schemes: http://, https://, Hosts: vt.tiktok.com, www.tiktokv.com, t.tiktok.com, www.tiktok.com, Path Prefixes: /, /i18n/share, /share, /redirect, /tag/, /music/, /sticker/, Path Patterns: /@.*,

    com.tencent.tauth.AuthActivity Schemes: \ 110560287://, com.ss.android.ugc.aweme.app.DeepLinkHandlerActivity Schemes: snssdk1180://, musically://, snssdk1233://, tiktok://, com.ss.android.sdk.activity.BootstrapActivity Schemes: snssdk0://, com.linecorp.linesdk.auth.internal.LineAuthenticationCallbackActivity Schemes: lineauth://,

    MANIFEST ANALYSIS

    ISSUE SEVERITY DESCRIPTION

    App has a Network Security Configuration[android:networkSecurityConfig] info

    The Network Security Configuration feature lets apps customizetheir network security settings in a safe, declarativeconfiguration file without modifying app code. These settingscan be configured for specific domains and for a specific app.

    Launch Mode of Activity (com.ss.android.ugc.aweme.share.ShareScreenShotActivity) isnot standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity(com.ss.android.ugc.trill.openauthorize.AwemeAuthorizedActivity) is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Activity (com.ss.android.ugc.trill.openauthorize.AwemeAuthorizedActivity) is notProtected. [android:exported=true]

    highAn Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Activity (net.openid.appauth.RedirectUriReceiverActivity) is not Protected.An intent-filter exists. high

    An Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Activityis explicitly exported.

    Launch Mode of Activity (com.ss.android.ugc.aweme.app.AppLinkHandler) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Activity (com.ss.android.ugc.aweme.app.AppLinkHandler) is not Protected.An intent-filter exists. high

    An Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Activityis explicitly exported.

    Launch Mode of Activity (com.ss.android.ugc.aweme.share.SystemShareActivity) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Activity (com.ss.android.ugc.aweme.share.SystemShareActivity) is not Protected.An intent-filter exists. high

    An Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Activityis explicitly exported.

    Launch Mode of Activity (com.tencent.tauth.AuthActivity) is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Activity (com.tencent.tauth.AuthActivity) is not Protected.An intent-filter exists. high

    An Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Activityis explicitly exported.

    Activity (com.ss.android.ugc.aweme.detail.ui.DetailActivity) is not Protected.An intent-filter exists. high

    An Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Activityis explicitly exported.

    Launch Mode of Activity (com.ss.android.ugc.aweme.app.LogListActivity) is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.ss.android.ugc.aweme.app.debug.AbTestSettingActivity) isnot standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.ss.android.ugc.aweme.account.ui.RecoverAccountActivity)is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

  • Launch Mode of Activity (com.ss.android.ugc.aweme.app.DeepLinkHandlerActivity) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Activity (com.ss.android.ugc.aweme.app.DeepLinkHandlerActivity) is not Protected.An intent-filter exists. high

    An Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Activityis explicitly exported.

    Broadcast Receiver (com.ss.android.ugc.aweme.common.net.NetworkReceiver) is notProtected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Launch Mode of Activity (com.ss.android.ugc.aweme.mobile.EditProfileActivityV2) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.ss.android.ugc.aweme.login.ui.RecommendFriendActivity) isnot standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Broadcast Receiver (com.ss.android.common.applog.HotsoonReceiver) is not Protected.An intent-filter exists. high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Launch Mode of Activity (com.ss.android.ugc.aweme.ttplatformapi.TtAuthorizeActivity) isnot standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Activity (com.ss.android.ugc.aweme.ttplatformapi.TtAuthorizeActivity) is not Protected. [android:exported=true] high

    An Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Content Provider (com.ss.android.ttplatformsdk.provider.TTPlatformAccountProvider) isnot Protected. [android:exported=true]

    highA Content Provider is found to be shared with other apps on thedevice therefore leaving it accessible to any other applicationon the device.

    Content Provider (com.ss.android.ugc.aweme.livewallpaper.WallPaperDataProvider) isnot Protected. [android:exported=true]

    highA Content Provider is found to be shared with other apps on thedevice therefore leaving it accessible to any other applicationon the device.

    Service (com.ss.android.ugc.aweme.livewallpaper.AmeLiveWallpaper) is Protected by apermission, but the protection level of the permission should be checked.Permission: android.permission.BIND_WALLPAPER [android:exported=true]

    high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. It is protected by a permission which is not defined inthe analysed application. As a result, the protection level of thepermission should be checked where it is defined. If it is set tonormal or dangerous, a malicious application can request andobtain the permission and interact with the component. If it isset to signature, only applications signed with the samecertificate can obtain the permission.

    Activity (com.ss.android.ugc.aweme.livewallpaper.ui.LiveWallPaperPreviewActivity) is notProtected. [android:exported=true]

    highAn Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Broadcast Receiver(com.ss.android.ugc.aweme.livewallpaper.receiver.LiveWallPaperPluginInstalledReceiver)is not Protected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Service (com.ss.ttm.player.TTPlayerService) is not Protected. [android:exported=true] high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Broadcast Receiver(com.ss.android.socialbase.downloader.downloader.DownloadReceiver) is not Protected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Activity-Alias (com.ss.android.ugc.aweme.splash.SplashActivity) is not Protected.An intent-filter exists. high

    An Activity-Alias is found to be shared with other apps on thedevice therefore leaving it accessible to any other applicationon the device. The presence of intent-filter indicates that theActivity-Alias is explicitly exported.

    Launch Mode of Activity (com.ss.android.ugc.trill.main.shortcut.ShortcutShootingActivity)is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.ss.android.ugc.trill.main.shortcut.ShortcutMessageActivity)is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.ss.android.ugc.trill.main.shortcut.ShortcutTrendingActivity)is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity(com.ss.android.ugc.aweme.comment.share.I18nCommentShareActivity) is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Service (com.ss.android.ugc.trill.account.TiktokAuthService) is not Protected. [android:exported=true] high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Broadcast Receiver (com.appsflyer.MultipleInstallBroadcastReceiver) is not Protected. [android:exported=true] high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device.

    Broadcast Receiver (com.appsflyer.SingleInstallBroadcastReceiver) is not Protected. [android:exported=true] high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device.

    ISSUE SEVERITY DESCRIPTION

  • Broadcast Receiver (com.ss.android.ugc.trill.abtest.impl.NotificationBroadcastReceiver)is not Protected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Broadcast Receiver (com.bytedance.ttnet.hostmonitor.ConnectivityReceiver) is notProtected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Content Provider (com.ss.android.common.util.MultiProcessSharedProvider) is notProtected. [android:exported=true]

    highA Content Provider is found to be shared with other apps on thedevice therefore leaving it accessible to any other applicationon the device.

    Broadcast Receiver (com.ss.android.ugc.aweme.common.net.NetWorkStateReceiver) isnot Protected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Launch Mode of Activity (com.ss.android.ugc.aweme.app.PushCameraBlurActivity) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.ss.android.ugc.aweme.antiaddic.lock.ui.TimeUnlockActivity)is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Broadcast Receiver (com.ss.android.message.MessageReceiver) is not Protected.An intent-filter exists. high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Broadcast Receiver (com.ss.android.downloadlib.core.download.DownloadReceiver) isnot Protected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Broadcast Receiver (com.ss.android.socialbase.appdownloader.DownloadReceiver) isnot Protected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Launch Mode of Activity (com.ss.android.ugc.aweme.journey.NewUserJourneyActivity) isnot standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Service (com.ss.android.ugc.aweme.tile.PublishTileService) is Protected by a permission,but the protection level of the permission should be checked.Permission: android.permission.BIND_QUICK_SETTINGS_TILE [android:exported=true]

    high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. It is protected by a permission which is not defined inthe analysed application. As a result, the protection level of thepermission should be checked where it is defined. If it is set tonormal or dangerous, a malicious application can request andobtain the permission and interact with the component. If it isset to signature, only applications signed with the samecertificate can obtain the permission.

    Service (com.ss.android.ugc.aweme.tile.HotVideoTileService) is Protected by apermission, but the protection level of the permission should be checked.Permission: android.permission.BIND_QUICK_SETTINGS_TILE [android:exported=true]

    high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. It is protected by a permission which is not defined inthe analysed application. As a result, the protection level of thepermission should be checked where it is defined. If it is set tonormal or dangerous, a malicious application can request andobtain the permission and interact with the component. If it isset to signature, only applications signed with the samecertificate can obtain the permission.

    Broadcast Receiver(com.ss.android.ugc.aweme.share.systemshare.SystemShareTargetChosenReceiver) isnot Protected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Activity (com.ss.android.sdk.activity.BootstrapActivity) is not Protected.An intent-filter exists. high

    An Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Activityis explicitly exported.

    Launch Mode of Activity (com.ss.android.ugc.aweme.live.LiveBgBroadcastActivity) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.ss.android.ugc.aweme.live.LivePlayActivity) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.ss.android.ugc.aweme.app.LiveBroadcastSigningActivity) isnot standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.ss.android.ugc.aweme.miniapp.MiniAppListH5Activity) isnot standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Service (com.ss.android.http.OpenUrlService) is not Protected.An intent-filter exists. high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Service isexplicitly exported.

    Service (com.ss.android.message.NotifyService) is not Protected. [android:exported=true] high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Service (com.ss.android.message.log.LogService) is not Protected. [android:exported=true] high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    ISSUE SEVERITY DESCRIPTION

  • TaskAffinity is set for Activity (com.ss.android.message.sswo.SswoActivity) high

    If taskAffinity is set, then other application could read theIntents sent to Activities belonging to another task. Always usethe default setting keeping the affinity as the package name inorder to prevent sensitive information inside sent or receivedIntents from being read by another application.

    Launch Mode of Activity (com.ss.android.message.sswo.SswoActivity) is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Service (com.igexin.sdk.PushService) is not Protected. [android:exported=true] high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Broadcast Receiver (com.igexin.sdk.PushReceiver) is not Protected. [android:exported=true] high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device.

    Broadcast Receiver(com.ss.android.ugc.awemepushlib.os.receiver.NotificationBroadcastReceiver) is notProtected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Service (cn.jpush.android.service.DaemonService) is not Protected. [android:exported=true] high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Launch Mode of Activity (com.ss.android.ugc.aweme.im.sdk.chat.ChatRoomActivity) isnot standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity(com.ss.android.ugc.aweme.im.sdk.module.session.SessionListActivity) is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.ss.android.ugc.aweme.tools.draft.DraftBoxActivity) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Service (com.ss.android.ugc.aweme.tools.policysecurity.OriginalSoundUploadService) isProtected by a permission, but the protection level of the permission should be checked.Permission: android.permission.BIND_JOB_SERVICE [android:exported=true]

    high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. It is protected by a permission which is not defined inthe analysed application. As a result, the protection level of thepermission should be checked where it is defined. If it is set tonormal or dangerous, a malicious application can request andobtain the permission and interact with the component. If it isset to signature, only applications signed with the samecertificate can obtain the permission.

    Service (com.ss.android.ugc.aweme.tools.extract.upload.VideoFramesUploadService) isProtected by a permission, but the protection level of the permission should be checked.Permission: android.permission.BIND_JOB_SERVICE [android:exported=true]

    high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. It is protected by a permission which is not defined inthe analysed application. As a result, the protection level of thepermission should be checked where it is defined. If it is set tonormal or dangerous, a malicious application can request andobtain the permission and interact with the component. If it isset to signature, only applications signed with the samecertificate can obtain the permission.

    Launch Mode of Activity (com.ss.android.ugc.aweme.shortvideo.ui.VideoPublishActivity)is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity(com.ss.android.ugc.aweme.shortvideo.ui.VideoRecordPermissionActivity) is notstandard.

    high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Activity (com.ss.android.ugc.aweme.shortvideo.ui.VideoRecordPermissionActivity) is notProtected.An intent-filter exists.

    high

    An Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Activityis explicitly exported.

    Launch Mode of Activity(com.ss.android.ugc.aweme.shortvideo.ui.VideoRecordNewActivity) is not standard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Content Provider (com.facebook.FacebookContentProvider) is not Protected. [android:exported=true] high

    A Content Provider is found to be shared with other apps on thedevice therefore leaving it accessible to any other applicationon the device.

    Launch Mode of Activity (com.ss.android.downloadlib.activity.TTDelegateActivity) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.bytedance.jirafast.ui.JIRAReportEntryActivity) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.bytedance.jirafast.ui.JIRACreateIssueActivity) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    TaskAffinity is set for Activity (com.tt.miniapphost.placeholder.MiniappTabActivity0) high

    If taskAffinity is set, then other application could read theIntents sent to Activities belonging to another task. Always usethe default setting keeping the affinity as the package name inorder to prevent sensitive information inside sent or receivedIntents from being read by another application.

    ISSUE SEVERITY DESCRIPTION

  • Launch Mode of Activity (com.tt.miniapphost.placeholder.MiniappTabActivity0) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    TaskAffinity is set for Activity (com.tt.miniapphost.placeholder.MiniappTabActivity1) high

    If taskAffinity is set, then other application could read theIntents sent to Activities belonging to another task. Always usethe default setting keeping the affinity as the package name inorder to prevent sensitive information inside sent or receivedIntents from being read by another application.

    Launch Mode of Activity (com.tt.miniapphost.placeholder.MiniappTabActivity1) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    TaskAffinity is set for Activity (com.tt.miniapphost.placeholder.MiniappTabActivity2) high

    If taskAffinity is set, then other application could read theIntents sent to Activities belonging to another task. Always usethe default setting keeping the affinity as the package name inorder to prevent sensitive information inside sent or receivedIntents from being read by another application.

    Launch Mode of Activity (com.tt.miniapphost.placeholder.MiniappTabActivity2) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    TaskAffinity is set for Activity (com.tt.miniapphost.placeholder.MiniappTabActivity3) high

    If taskAffinity is set, then other application could read theIntents sent to Activities belonging to another task. Always usethe default setting keeping the affinity as the package name inorder to prevent sensitive information inside sent or receivedIntents from being read by another application.

    Launch Mode of Activity (com.tt.miniapphost.placeholder.MiniappTabActivity3) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    TaskAffinity is set for Activity (com.tt.miniapphost.placeholder.MiniappTabActivity4) high

    If taskAffinity is set, then other application could read theIntents sent to Activities belonging to another task. Always usethe default setting keeping the affinity as the package name inorder to prevent sensitive information inside sent or receivedIntents from being read by another application.

    Launch Mode of Activity (com.tt.miniapphost.placeholder.MiniappTabActivity4) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Launch Mode of Activity (com.tt.miniapp.feedback.FeedbackRecordActivity) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Service (com.ss.android.ugc.asve.sandbox.SandBoxRemoteCoreService) is not Protected.An intent-filter exists. high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Service isexplicitly exported.

    Service (com.fcm.service.SSGcmListenerService) is not Protected.An intent-filter exists. high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Service isexplicitly exported.

    Service (androidx.work.impl.background.systemjob.SystemJobService) is Protected by apermission, but the protection level of the permission should be checked.Permission: android.permission.BIND_JOB_SERVICE [android:exported=true]

    high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. It is protected by a permission which is not defined inthe analysed application. As a result, the protection level of thepermission should be checked where it is defined. If it is set tonormal or dangerous, a malicious application can request andobtain the permission and interact with the component. If it isset to signature, only applications signed with the samecertificate can obtain the permission.

    Broadcast Receiver(androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy) isnot Protected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Broadcast Receiver(androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy) isnot Protected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Broadcast Receiver(androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy) isnot Protected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Broadcast Receiver(androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy) is notProtected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Broadcast Receiver (androidx.work.impl.background.systemalarm.RescheduleReceiver)is not Protected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Broadcast Receiver (com.ss.android.ugc.rhea.receiver.ControllerReceiver) is notProtected. [android:exported=true]

    highA Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device.

    Service (com.bytedance.common.wschannel.server.WsChannelService) is not Protected. [android:exported=true] high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Service (com.bytedance.common.wschannel.client.WsClientService) is not Protected. [android:exported=true] high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Content Provider(com.bytedance.common.wschannel.WsChannelMultiProcessSharedProvider) is notProtected. [android:exported=true]

    highA Content Provider is found to be shared with other apps on thedevice therefore leaving it accessible to any other applicationon the device.

    ISSUE SEVERITY DESCRIPTION

  • Service (com.google.android.gms.auth.api.signin.RevocationBoundService) is Protectedby a permission, but the protection level of the permission should be checked.Permission:com.google.android.gms.auth.api.signin.permission.REVOCATION_NOTIFICATION [android:exported=true]

    high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. It is protected by a permission which is not defined inthe analysed application. As a result, the protection level of thepermission should be checked where it is defined. If it is set tonormal or dangerous, a malicious application can request andobtain the permission and interact with the component. If it isset to signature, only applications signed with the samecertificate can obtain the permission.

    Broadcast Receiver(com.google.android.gms.measurement.AppMeasurementInstallReferrerReceiver) isProtected by a permission, but the protection level of the permission should be checked.Permission: android.permission.INSTALL_PACKAGES [android:exported=true]

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. It is protected by a permission whichis not defined in the analysed application. As a result, theprotection level of the permission should be checked where it isdefined. If it is set to normal or dangerous, a maliciousapplication can request and obtain the permission and interactwith the component. If it is set to signature, only applicationssigned with the same certificate can obtain the permission.

    Service (com.google.firebase.messaging.FirebaseMessagingService) is not Protected. [android:exported=true] high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Broadcast Receiver (com.google.firebase.iid.FirebaseInstanceIdReceiver) is Protectedby a permission, but the protection level of the permission should be checked.Permission: com.google.android.c2dm.permission.SEND [android:exported=true]

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. It is protected by a permission whichis not defined in the analysed application. As a result, theprotection level of the permission should be checked where it isdefined. If it is set to normal or dangerous, a maliciousapplication can request and obtain the permission and interactwith the component. If it is set to signature, only applicationssigned with the same certificate can obtain the permission.

    Service (com.google.firebase.iid.FirebaseInstanceIdService) is not Protected. [android:exported=true] high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Broadcast Receiver (com.facebook.CampaignTrackingReceiver) is Protected by apermission, but the protection level of the permission should be checked.Permission: android.permission.INSTALL_PACKAGES [android:exported=true]

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. It is protected by a permission whichis not defined in the analysed application. As a result, theprotection level of the permission should be checked where it isdefined. If it is set to normal or dangerous, a maliciousapplication can request and obtain the permission and interactwith the component. If it is set to signature, only applicationssigned with the same certificate can obtain the permission.

    Launch Mode of Activity (net.openid.appauth.AuthorizationManagementActivity) is notstandard. high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Service (com.bytedance.ies.common.push.account.AccountSyncService) is not Protected. [android:exported=true] high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    Service (com.bytedance.ies.common.push.account.AuthenticatorService) is notProtected.An intent-filter exists.

    high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Service isexplicitly exported.

    Broadcast Receiver (com.ss.android.push.window.oppo.ScreenReceiver) is notProtected.An intent-filter exists.

    high

    A Broadcast Receiver is found to be shared with other apps onthe device therefore leaving it accessible to any otherapplication on the device. The presence of intent-filter indicatesthat the Broadcast Receiver is explicitly exported.

    Service (com.ss.android.newmedia.redbadge.RedbadgeHandler) is not Protected.An intent-filter exists. high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Service isexplicitly exported.

    Launch Mode of Activity(com.ss.android.socialbase.appdownloader.view.DownloadTaskDeleteActivity) is notstandard.

    high

    An Activity should not be having the launch mode attribute setto "singleTask/singleInstance" as it becomes root Activity and itis possible for other applications to read the contents of thecalling Intent. So it is required to use the "standard" launchmode attribute when sensitive information is included in anIntent.

    Service(com.ss.android.socialbase.downloader.downloader.IndependentProcessDownloadService)is not Protected.An intent-filter exists.

    high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. The presence of intent-filter indicates that the Service isexplicitly exported.

    Service (com.ss.android.socialbase.downloader.impls.RetryJobSchedulerService) isProtected by a permission, but the protection level of the permission should be checked.Permission: android.permission.BIND_JOB_SERVICE [android:exported=true]

    high

    A Service is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice. It is protected by a permission which is not defined inthe analysed application. As a result, the protection level of thepermission should be checked where it is defined. If it is set tonormal or dangerous, a malicious application can request andobtain the permission and interact with the component. If it isset to signature, only applications signed with the samecertificate can obtain the permission.

    Activity (com.linecorp.linesdk.auth.internal.LineAuthenticationCallbackActivity) is notProtected. [android:exported=true]

    highAn Activity is found to be shared with other apps on the devicetherefore leaving it accessible to any other application on thedevice.

    ISSUE SEVERITY DESCRIPTION

    CODE ANALYSIS

    ISSUE SEVERITY CVSS CWE OWASP FILESc\a\s.java c\a\e\j\j.java c\a\e\j\l.java com\airbnb\lottie\c\b.java com\airbnb\lottie\c\d.java com\airbnb\lottie\c\h.java com\airbnb\lottie\d\c.java com\airbnb\lottie\e\a.java com\airbnb\lottie\e\aa.java com\airbnb\lottie\e\ab.java com\airbnb\lottie\e\ad.java com\airbnb\lottie\e\ae.java com\airbnb\lottie\e\af.java com\airbnb\lottie\e\ag.java

    file:///C:/Users/Salty/AppData/Local/ViewSource/?file=c%5Ca%5Cs.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=c%5Ca%5Ce%5Cj%5Cj.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=c%5Ca%5Ce%5Cj%5Cl.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Cc%5Cb.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Cc%5Cd.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Cc%5Ch.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Cd%5Cc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Ca.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Caa.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cab.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cad.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cae.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Caf.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cag.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apk

  • com\airbnb\lottie\e\ah.java com\airbnb\lottie\e\ai.java com\airbnb\lottie\e\b.java com\airbnb\lottie\e\c.java com\airbnb\lottie\e\e.java com\airbnb\lottie\e\g.java com\airbnb\lottie\e\h.java com\airbnb\lottie\e\j.java com\airbnb\lottie\e\k.java com\airbnb\lottie\e\m.java com\airbnb\lottie\e\n.java com\airbnb\lottie\e\p.java com\airbnb\lottie\e\q.java com\airbnb\lottie\e\r.java com\airbnb\lottie\e\s.java com\airbnb\lottie\e\t.java com\airbnb\lottie\e\u.java com\airbnb\lottie\e\v.java com\airbnb\lottie\e\z.java com\appsflyer\AppsFlyer2dXConversionCallback.java com\appsflyer\i.java com\bytedance\ad\symphony\nativead\admob\AdMobNativeAdProvider.java com\bytedance\android\a\a\d\a.java com\bytedance\android\c\b\a\b.java com\bytedance\android\live\base\c.java com\bytedance\android\live\base\model\ImageModel.java com\bytedance\android\live\base\model\live\RoomStats.java com\bytedance\android\live\base\model\user\c.java com\bytedance\android\live\base\model\user\f.java com\bytedance\android\live\base\model\user\h.java com\bytedance\android\live\base\model\user\m.java com\bytedance\android\live\base\model\user\PlatformBindInfo.java com\bytedance\android\live\base\model\user\User.java com\bytedance\android\live\broadcast\c.java com\bytedance\android\live\broadcast\bgbroadcast\c.java com\bytedance\android\live\broadcast\effect\model\FilterModel.java com\bytedance\android\live\broadcast\model\c.java com\bytedance\android\live\broadcast\share\a.java com\bytedance\android\live\broadcast\widget\StickerTipW idget.java com\bytedance\android\live\broadcast\widget\VideoW idget2.java com\bytedance\android\live\core\a\g.java com\bytedance\android\live\core\a\k.java com\bytedance\android\live\core\a\p.java com\bytedance\android\live\core\rxutils\a\a\c.java com\bytedance\android\live\wallet\a\b.java com\bytedance\android\livesdk\banner\InRoomBannerManager.java com\bytedance\android\livesdk\blockword\a\a.java com\bytedance\android\livesdk\blockword\a\b.java com\bytedance\android\livesdk\blockword\a\c.java com\bytedance\android\livesdk\browser\h\c.java com\bytedance\android\livesdk\browser\jsbridge\c\e.java com\bytedance\android\livesdk\browser\jsbridge\c\i.java com\bytedance\android\livesdk\browser\jsbridge\newmethods\ad.java com\bytedance\android\livesdk\browser\jsbridge\newmethods\ae.java com\bytedance\android\livesdk\browser\jsbridge\newmethods\af.java com\bytedance\android\livesdk\browser\jsbridge\newmethods\aj.java com\bytedance\android\livesdk\browser\jsbridge\newmethods\au.java com\bytedance\android\livesdk\browser\jsbridge\newmethods\bp.java com\bytedance\android\livesdk\browser\jsbridge\newmethods\m.java com\bytedance\android\livesdk\browser\jsbridge\newmethods\n.java com\bytedance\android\livesdk\chatroom\event\ak.java com\bytedance\android\livesdk\chatroom\event\al.java com\bytedance\android\livesdk\chatroom\event\am.java com\bytedance\android\livesdk\chatroom\interact\LinkInRoomVideoAnchorW idget.java com\bytedance\android\livesdk\chatroom\interact\h\fp.java com\bytedance\android\livesdk\chatroom\interact\h\fq.java com\bytedance\android\livesdk\chatroom\interact\h\gh.java com\bytedance\android\livesdk\chatroom\model\ak.java com\bytedance\android\livesdk\chatroom\model\al.java com\bytedance\android\livesdk\chatroom\model\am.java com\bytedance\android\livesdk\chatroom\model\ao.java com\bytedance\android\livesdk\chatroom\presenter\bv.java com\bytedance\android\livesdk\chatroom\presenter\cc.java com\bytedance\android\livesdk\chatroom\ui\b.java com\bytedance\android\livesdk\chatroom\ui\cc.java com\bytedance\android\livesdk\chatroom\viewmodule\ActionMessageW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\BarrageW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\BottomRightBannerContainerW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\BottomRightBannerW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\CommentW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\DailyRankW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\DecorationWrapperW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\dw.java com\bytedance\android\livesdk\chatroom\viewmodule\EnterAnimW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\er.java com\bytedance\android\livesdk\chatroom\viewmodule\FullVideoButtonW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\GiftRelayW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\GiftW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\HourRankForDyW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\LinkControlW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\LinkCrossRoomWidget.java com\bytedance\android\livesdk\chatroom\viewmodule\LinkPKMvpW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\LinkPKStealTowerW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\LinkPkTaskW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\LinkPKW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\LiveShareW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\NormalGiftAnimW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\PreloadWebViewW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\PromotionStatusW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\RechargeW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\RoomPushW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\TextMessageW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\TopHourRankW idget.java com\bytedance\android\livesdk\chatroom\viewmodule\a\d.java com\bytedance\android\livesdk\chatroom\viewmodule\toolbar\LiveToolbarW idget.java com\bytedance\android\livesdk\chatroom\widget\a.java com\bytedance\android\livesdk\chatroom\widget\LiveRoomOnlineUserW idget.java com\bytedance\android\livesdk\chatroom\widget\LiveRoomUserInfoW idget.java com\bytedance\android\livesdk\chatroom\widget\LiveRoomWatchUserW idget.java com\bytedance\android\livesdk\fansclub\LiveFansClubEntryW idget.java com\bytedance\android\livesdk\feed\feed\FeedDataKey.java com\bytedance\android\livesdk\feed\h\t.java com\bytedance\android\livesdk\feed\n\h.java com\bytedance\android\livesdk\floatwindow\i.java

    ISSUE SEVERITY CVSS CWE OWASP FILES

    file:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cah.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cai.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cb.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Ce.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cg.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Ch.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cj.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Ck.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cm.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cn.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cp.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cq.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cr.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cs.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Ct.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cu.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cv.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cairbnb%5Clottie%5Ce%5Cz.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cappsflyer%5CAppsFlyer2dXConversionCallback.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cappsflyer%5Ci.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Cad%5Csymphony%5Cnativead%5Cadmob%5CAdMobNativeAdProvider.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Ca%5Ca%5Cd%5Ca.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Cc%5Cb%5Ca%5Cb.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbase%5Cc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbase%5Cmodel%5CImageModel.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbase%5Cmodel%5Clive%5CRoomStats.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbase%5Cmodel%5Cuser%5Cc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbase%5Cmodel%5Cuser%5Cf.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbase%5Cmodel%5Cuser%5Ch.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbase%5Cmodel%5Cuser%5Cm.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbase%5Cmodel%5Cuser%5CPlatformBindInfo.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbase%5Cmodel%5Cuser%5CUser.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbroadcast%5Cc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbroadcast%5Cbgbroadcast%5Cc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbroadcast%5Ceffect%5Cmodel%5CFilterModel.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbroadcast%5Cmodel%5Cc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbroadcast%5Cshare%5Ca.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbroadcast%5Cwidget%5CStickerTipWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cbroadcast%5Cwidget%5CVideoWidget2.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Ccore%5Ca%5Cg.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Ccore%5Ca%5Ck.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Ccore%5Ca%5Cp.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Ccore%5Crxutils%5Ca%5Ca%5Cc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clive%5Cwallet%5Ca%5Cb.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbanner%5CInRoomBannerManager.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cblockword%5Ca%5Ca.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cblockword%5Ca%5Cb.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cblockword%5Ca%5Cc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbrowser%5Ch%5Cc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbrowser%5Cjsbridge%5Cc%5Ce.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbrowser%5Cjsbridge%5Cc%5Ci.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbrowser%5Cjsbridge%5Cnewmethods%5Cad.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbrowser%5Cjsbridge%5Cnewmethods%5Cae.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbrowser%5Cjsbridge%5Cnewmethods%5Caf.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbrowser%5Cjsbridge%5Cnewmethods%5Caj.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbrowser%5Cjsbridge%5Cnewmethods%5Cau.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbrowser%5Cjsbridge%5Cnewmethods%5Cbp.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbrowser%5Cjsbridge%5Cnewmethods%5Cm.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cbrowser%5Cjsbridge%5Cnewmethods%5Cn.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cevent%5Cak.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cevent%5Cal.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cevent%5Cam.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cinteract%5CLinkInRoomVideoAnchorWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cinteract%5Ch%5Cfp.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cinteract%5Ch%5Cfq.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cinteract%5Ch%5Cgh.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cmodel%5Cak.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cmodel%5Cal.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cmodel%5Cam.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cmodel%5Cao.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cpresenter%5Cbv.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cpresenter%5Ccc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cui%5Cb.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cui%5Ccc.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CActionMessageWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CBarrageWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CBottomRightBannerContainerWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CBottomRightBannerWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CCommentWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CDailyRankWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CDecorationWrapperWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5Cdw.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CEnterAnimWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5Cer.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CFullVideoButtonWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CGiftRelayWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CGiftWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CHourRankForDyWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CLinkControlWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CLinkCrossRoomWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CLinkPKMvpWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CLinkPKStealTowerWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CLinkPkTaskWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CLinkPKWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CLiveShareWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CNormalGiftAnimWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CPreloadWebViewWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CPromotionStatusWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CRechargeWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSource/?file=com%5Cbytedance%5Candroid%5Clivesdk%5Cchatroom%5Cviewmodule%5CRoomPushWidget.java&md5=7d38c0b9ff3bf6b4503e75c4e8e7cc08&type=apkfile:///C:/Users/Salty/AppData/Local/ViewSour