Mobile Intent Test Lab

Use this page to test Android browser intent behavior from different trigger methods. Compare how each action behaves in your app WebView, Chrome, and Samsung Internet.

No automatic redirect runs on load so you can test each method explicitly.

Collecting environment diagnostics...

Recommended first test: tap one of the direct intent anchors below. Many browsers block intent launches triggered by timers or indirect JavaScript flows.

Regular HTTPS URL:

https://www.example.com/

Android intent URL (targets Samsung Internet package):

Android intent URL (Samsung action variant from CVE-2022-2856 reports):

Android intent URL (targets Chrome package):

Open Regular HTTPS Link Open Samsung Intent (direct anchor tap) Open Samsung Intent (action variant) Open Chrome Intent (direct anchor tap)

Expected on patched Chrome: opening another browser with attacker-controlled data should require explicit user confirmation, or be blocked/fallback depending on context.

Result Matrix

Set status for each method after testing in each app/browser context.

Case Status Set Notes
Verdict pending. Set matrix statuses to compute risk.
PASS0
FAIL0
BLOCKED0
N/A0
UNSET0

Auto-generated finding text for your pentest notes:

Event Log
No events yet.