Security Research Trigger Page | innora.ai
Opens Alipay WebView and loads our PoC page which calls AlipayJSBridge APIs to collect GPS, device info, and demonstrate UI spoofing.
These DeepLinks open sensitive Alipay pages directly. No additional warning is shown.
1. Attacker distributes this page via SMS/WeChat/QQ (disguised as "red packet")
2. Victim clicks a button in their mobile browser
3. Browser triggers intent:// scheme which opens Alipay
4. For Chain A: Alipay loads attacker's page in WebView with AlipayJSBridge injected
5. For Chain B: Alipay navigates directly to sensitive page, no extra warning