DEF CON 33 - Bypassing Intent Destination Checks, LaunchAnyWhere Privilege Escalation - Qidan He @DEFCONConference
DEF CON 33 - Bypassing Intent Destination Checks, LaunchAnyWhere Privilege Escalation - Qidan He  @DEFCONConference
Uploaded October 2025 | Updated September 2026, 3 weeks ago
The LaunchAnywhere vulnerability has long been a significant concern in Android security, allowing unprivileged applications to invoke protected activities, even with system-level privileges, and have been actively exploited in the wild in the past.

In response, Google and device vendors have implemented patches, primarily by introducing destination component checks within privileged code before launching Intents. These fixes appeared to have mitigated such risks—at least on the surface. But has the threat truly been eliminated?

In this session, we demonstrate that these defenses remain insufficient. We introduce a new exploitation technique, BadResolve, which bypasses these checks through multiple methods, enabling a zero-permission app to achieve LaunchAnywhere once again. We reveal high-severity vulnerabilities that affect all Android versions, including the latest Android 16 (at time of writing), which have been confirmed and patched by Google. Dead, made alive again— we show how the LaunchAnywhere vulnerability has been reborn. In addition to presenting new exploitation techniques, we tackle the challenge of efficiently and accurately identifying methods in the vast codebases of AOSP and vendor-specific closed-source implementations that could be exploited by BadResolve, using LLM Agents and MCP.
DEF CON 33 - Bypassing Intent Destination Checks, LaunchAnyWhere Privilege Escalation - Qidan HeDEF CON 33 - Voting Village - Reflections on TTBR & Everest - Bowen, Blaze, Clark, Hoke, MulliganDEF CON 32 - If Existing Cyber Vulns Magically Disappeared, What Next - Dr  Stefanie TompkinsDEF CON 33 - Voting Village - A NY Legal Challenge to ExpressVote XLs Barcode Use - Susan LernerDEF CON 33 -  How malicious packages on npm bypass existing security tools - Paul McCartyDEF CON 33 - SCCM: The tree that always bears bad fruits - Mehdi kalimer0x00 ElyassaDEF CON 33 Recon Village -  Inside the Shadows Tracking RaaS Groups, Cyber Threats - John DilgenDEF CON 33 - Emulating Embedded Linux Devices at Scale w LightTouch Firmware Rehosting - S PolkeDEF CON 33  Voting Village - Risk Limiting Audits: What They Are and Arent - Philip StarkDEF CON 34 - Video Team - Ham Radio Village  - Marvin Goes HAMDEF CON 31 - The Art of Compromising C2 Servers  A Web App Vulns Perspective - Vangelis StykasDEF CON 32  - Manufacturing Lessons Learned, Lessons Taught - Tim Chase
DEFCONConference |

DEF CON 33 - Bypassing Intent Destination Checks, LaunchAnyWhere Privilege Escalation - Qidan He

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER