Philipp Beer

PhD Student · TU Wien · Web and Mobile Security

My research is centered on identifying and mitigating security issues and vulnerabilities within mobile-Web ecosystems. I hold a BSc and an MSc degree from TU Wien, where I am a member of the Security and Privacy Research Unit.

When I’m away from the keyboard, I spend my time on the bike, running, and doing HIIT. You’ll usually find me listening to indie music or catching a movie in the cinema.

Work philipp [dot] beer [at] tuwien [dot] ac [dot] at
Phone +43-1-58801-192610

Personal philipp [at] beerphilipp [dot] com

Philipp Beer presenting at the USENIX Security Symposium

Publications

2026

Plain Text, Plain Risks: Measuring HTTP Inclusion in Android WebViews at Scale

We measure cleartext HTTP usage in 189,779 Android apps and show how insecure WebView configurations enable attacks ranging from phishing to full app takeover.

AutoFail: Breaking Web Boundaries using Android’s Autofill Framework

We uncover vulnerabilities across Android’s Autofill pipeline that allow malicious pages to leak credentials, bypass origin isolation, and infer user accounts.

2025

TapTrap: Animation-Driven Tapjacking on Android

We introduce an animation-driven tapjacking attack that lets zero-permission Android apps bypass security prompts and trigger sensitive actions.

2024

Tabbed Out: Subverting the Android Custom Tab Security Model

We show how Android Custom Tabs enable cross-context tracking, SameSite cookie bypasses, phishing, and other violations of browser security boundaries.

2022

The Bridge between Web Applications and Mobile Platforms is Still Broken

We demonstrate how mobile WebView and Custom Tab integrations expose cross-site information and device sensors through broken app–Web boundaries.

Talks & Presentations

  • m0leCon 2026

    A tour of Android tapjacking’s evolution and TapTrap, an animation-based technique that bypasses modern overlay protections.

    Overlays and Beyond: Revisiting Tapjacking on Android
    Turin, Italy · March 2026

  • 3rd Vienna International Ethical Hacking Boot Camp (Workshop)

    A hands-on workshop examining how WebViews and Custom Tabs blur app–Web boundaries.

    When the Web Meets Apps: The Security Pitfalls of In-App Browsing
    Vienna, Austria · July 2025

  • Meta XS-Leaks Summit 2023

    An analysis of how Android Custom Tabs leak cross-context state, undermine SameSite protections, and enable phishing through UI customization.

    Cross-Context State Inference Attacks on Custom Tabs on Android
    London, United Kingdom · September 2023

Media & Outreach

CVEs

  • Chrome

    CVE-2025-3067

    Tapjacking on Chrome for Android.

  • Firefox

    CVE-2025-1939

    Tapjacking on Firefox for Android.

  • Chrome

    CVE-2023-3736

    Cross-origin information leakage on Chrome for Android.

  • Chrome

    CVE-2022-4926

    SameSite Cookie bypass on Chrome for Android.

  • Chrome

    CVE-2022-4188

    Injection of CORS-safelisted headers on Chrome for Android.