VAPT(Vulnerability Assessment and Penetration Testing ) team observed that android application allows to view information in recent apps screen while back grounding.
Risk:
Attacker or malicious application can extract information from the screen in the Recent Apps task switcher.
Added Event.DEACTIVATE in the main application page and in deactivate handler method try to active view as visible=false and alpha=0.
Not working in android 64 bit device.
Same code working on windows simulator.
Describe your problem in detail. Include the following information:
AIR SDK Version: 33.1.1.98
Device - Android 64 bit
VAPT(Vulnerability Assessment and Penetration Testing ) team observed that android application allows to view information in recent apps screen while back grounding. Risk: Attacker or malicious application can extract information from the screen in the Recent Apps task switcher.
Added Event.DEACTIVATE in the main application page and in deactivate handler method try to active view as visible=false and alpha=0. Not working in android 64 bit device. Same code working on windows simulator.
Describe your problem in detail. Include the following information: AIR SDK Version: 33.1.1.98 Device - Android 64 bit
Steps to Reproduce
Sample Code: <s:ViewNavigatorApplication xmlns:fx="http://ns.adobe.com/mxml/2009" xmlns:s="library://ns.adobe.com/flex/spark" firstView="views.TestAppHomeView" applicationDPI="240" activate="view1_activateHandler(event)" deactivate="view1_deactivateHandler(event)">
protected function view1_deactivateHandler(event:Event):void { if(this.navigator && this.navigator.activeView) { this.navigator.activeView.visible = false; this.navigator.activeView.alpha = 0; }
Sample Project: DeactivateEvent.zip
Sample Screen Content:
Not working on 64- bit Android device.
Working on Windows simulator
Known Workarounds
No Workarounds
Kindly let me know, how to hide the content when the app is in recent app section or background? Any workaround?