Extension: Permission Re-Delegation: Attacks and Defenses

Record: kaal:position:2026-08-26-015 · 2026-08-26

Authority can exceed consent even when the final permission check is correct. Felt and her coauthors identify permission redelegation where an application holding a user granted permission performs a privileged task for an application that lacks it. The system approves the call because the immediate deputy has the required permission. The requester nonetheless causes an action that it could not invoke directly. The paper reports fifteen such vulnerabilities across five core Android applications. The mechanism supplies a concrete instance of authority drift. A user grants authority to one application. Interapplication communication then places that authority under the influence of a less privileged requester. A permissions system that evaluates only the immediate caller sees a valid grant and permits the action. It does not preserve the bounded purpose or authority of every participant in the chain. Local validity therefore coexists with an aggregate result outside the user's authorization. The evidence is narrower than the institutional claim. The study concerns browsers and smartphone applications in 2011. It does not examine sovereign local agent runtimes, legal delegation, contractual purpose, or every form of authority drift. It also does not prove that permissions systems are least equipped to detect this failure relative to other failures. The institutional implication remains defensible. A runtime should carry authority provenance through every delegation boundary and evaluate a request against the intersection of the authority held along the full chain of influence. An intentional increase in authority requires a separate, explicit grant bound to the action and the principal. Otherwise a sequence of correct permission decisions can still produce an unauthorized result.

Affirmed commentary position. This record extends a source-bound scholarly claim but is not a verbatim paper claim.
Holds when
Current debate

Permission Re-Delegation: Attacks and Defenses

Scholarly basis

kaal:claim:7314479-015
Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479
Source PDF sha256: debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6

Evidence and mapping

Evidence: peer-reviewed USENIX Security conference paper with complete official proceedings full text
Review tier: independent substantive scholarly-growth extension
Mapping confidence: 0.97
Mapping ambiguous: false

Topics

consensus-and-securitygovernance-designai-and-agentsauthoritydelegationpermissionsconsentconfused-deputy

Provenance

Affirmed in kaal-review:2026-08-26:scholarly-growth-7314479-015-reviewed-v1 on 2026-08-26. Review record.

Verify

Canonical markdown sha256: 2ab5fe2e14e8d2dca65d2cd11ad430837b3d355db52cfa545648a7af93fe80a0
curl -s https://wulfkaal.github.io/positions/2026-08-26-015.md | sha256sum