Philipp Beer
PhD student at TU Wien exploring the intersection of Web and mobile security.
My research is centered on identifying and mitigating security issues and vulnerabilities within mobile-Web ecosystems. I hold a BSc and a MSc degree from TU Wien, where I am a member of the Security and Privacy Research Unit.
When I'm away from the keyboard, I spend my time on the bike, running, and doing HIIT. You'll usually find me listening to indie music (folk, rock, and pop) or catching a movie in the cinema.
No, that's not my dog :(
Work: philipp [dot] beer [at] tuwien [dot] ac [dot] at
Personal: philipp [at] beerphilipp [dot] com

Publications
NEWTapTrap: Animation-Driven Tapjacking on Android
@inproceedings{taptrap_beer,
author = {Philipp Beer and Marco Squarcina and Sebastian Roth and Martina Lindorfer},
title = {{TapTrap: Animation-Driven Tapjacking on Android}},
booktitle = {34th USENIX Security Symposium (USENIX Security 25)},
year = {2025},
address = {Seattle, WA},
publisher = {USENIX Association},
month = aug
}
Tabbed Out: Subverting the Android Custom Tab Security Model
We have responsibly disclosed all our findings to Google, which has already taken steps to apply targeted mitigations, assigned three CVEs for the discovered vulnerabilities, and awarded us $10,000 in bounties. Our interaction with Google led to clarifications of the CT security model in the new Chrome Custom Tabs Security FAQ document.
@inproceedings{beer_sp24,
title = {{Tabbed Out: Subverting the Android Custom Tab Security Model}},
author = {Beer, Philipp and Squarcina, Marco and Veronese, Lorenzo and Lindorfer, Martina},
booktitle = {Proceedings of the 45th IEEE Symposium on Security and Privacy (S\&P)},
location = {San Francisco, CA, USA},
year = {2024},
doi = {10.1109/SP54263.2024.00105}
}
The Bridge between Web Applications and Mobile Platforms is Still Broken
@misc{beer_secweb22,
title = {{The Bridge between Web Applications and Mobile Platforms is Still Broken}},
author = {Beer, Philipp and Veronese, Lorenzo and Squarcina, Marco and Lindorfer, Martina},
booktitle = {3rd IEEE Workshop on Designing Security for the Web (SecWeb)},
location = {San Francisco, CA, USA},
year = {2022}
}
Talks & Presentations
Meta XS-Leaks Summit 2023
Academic Service
- External Reviewer at the 46th IEEE Symposium on Security and Privacy (S&P) 2025
- Program Committee Member at the Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb) 2025
CVEs
CVE-2025-3067 Chrome 8.8 High
Tapjacking on Chrome for Android.
CVE-2025-1939 Firefox 3.9 Low
Tapjacking on Firefox for Android.
CVE-2023-3736 Chrome 4.3 Medium
Cross-origin information leakage on Chrome for Android.
CVE-2022-4926 Chrome 6.5 Medium
SameSite Cookie bypass on Chrome for Android.
CVE-2022-4188 Chrome 4.3 Medium
Injection of CORS-safelisted headers on Chrome for Android.