Structured Text Amplification - Vector 002
This post is the first in a series documenting the 32 vectors of Structured Text Amplification (STA). The complete whitepaper, version v5, covers the research, methodology, evidence, and full vector catalog.
During the development of the Structured Text Amplification (STA) research, a pattern emerged that initially could have appeared to be an isolated application behaviour: an unusually large structured input can affect the processing that occurs when a user interacts with a link and its context menu is constructed.
This behaviour was documented as STA-002 within the research catalog.
The significance of STA-002 does not lie in presenting the greatest impact among all vectors. It lies in something more interesting from a research perspective:
The STA pattern can appear even in seemingly basic interaction surfaces.
This raises a question that will run through this entire series:
If a structured input can generate a disproportionate cost in a surface as simple as a context menu, what happens when that same input traverses deeper layers of the system?
Affected browsers and devices
STA-002 was observed in the following context:
Browsers: Google Chrome, Microsoft Edge, and other Chromium-based browsers on Android. The behaviour is not specific to a single browser engine; it appears in the interaction between the browser and the Android framework's context menu construction.
Devices tested: The behaviour was reproduced on multiple production devices across different OEMs, including:
- Xiaomi Redmi Note 14 5G (HyperOS 3.0 / Android 16)
- Google Pixel 7 (Android 13–15)
- Samsung Galaxy series (One UI, Android 14–15)
- OPPO A78 / A6 5G (ColorOS, Android 14–16)
- OnePlus 11 (OxygenOS, Android 14)
This cross-OEM recurrence suggests the issue is not a manufacturer-specific customization, but rather a pattern present in the shared Android framework and browser interaction paths.
Timeline
The following timeline documents the discovery and reporting of STA-002:
| Date | Event |
| 28 Aug 2022 | Original observation: TransactionTooLargeException / DeadSystemException in Firefox Focus & Nightly during clipboard, share, and open-in-app actions. |
| 12 Oct 2022 | First public advisory published: "Mozilla Firefox Focus and Nightly for Android Remote Crash DoS" (lostmon.blogspot.com). |
| Nov 2022 | Chromium Issue 40879254 opened. Security labels removed; partial UX patch applied; issue remained open. |
| Nov 2022 | Mozilla Bugzilla #1802594 (S3) opened — still NEW / unresolved as of 2026. |
| 20 Jan 2026 | Formal report to Google Android VRP (A-477279924) and Microsoft MSRC. Chrome VRP filing covering 27 vectors (Issue 477202817) closed same day as "Won't Fix (Intended Behavior)". |
| Feb 2026 | Whitepaper v4 distributed (27 vectors). |
| 24 May 2026 | Chrome bugreport captures two full native ANRs, establishing STA-017 as Tier A. |
| 30 Jul 2026 | Public whitepaper disclosure — lostmon.blogspot.com. |
| Aug 2026 | STA-001 published as part of the public blog series documenting all 32 STA vectors. |
The scenario
The scenario is straightforward:
Web page
│
▼
Link with an unusually large URL
│
▼
User long-presses the link
│
▼
Browser / Android builds the context menu
│
▼
Processing of the URL content
│
▼
Anomalous behaviour / degradation
The important characteristic is that the user does not need to perform a technically complex operation.
The interaction is apparently normal:
long-pressing a link.
However, that action causes the content associated with the link to traverse an additional processing chain.
Where does amplification appear?
The STA model studies precisely this type of path.
A structured input — in this case, a URL — enters an interaction surface and may end up being processed by different layers.
The important point is not solely the initial size of the input, but the cost it can acquire during its processing and propagation.
The conceptual path can be represented as follows:
INPUT │ │ Structured URL ▼ Browser │ │ selection / context ▼ Context-menu processing │ │ transformation / analysis ▼ Text processing │ ▼ Cost amplification
Therefore:
The size of the input data does not necessarily represent the final cost of processing it.
That is one of the principles that STA seeks to study.
Trigger
The documented trigger for STA-002 is:
Long-press on link → context menu
In the whitepaper's catalog, STA-002 appears with an estimated CVSS of 3.7.
(CVSS 3.1: AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
This rating corresponds to a scenario of limited impact, requiring user interaction and with no persistence.
This is important because STA-002 should not be confused with later vectors in the research that present persistence or systemic impacts.
Persistence
A relevant characteristic of STA-002 is precisely its lack of persistence.
The behaviour is associated with the processing that occurs during interaction with the context menu.
There is no documented evidence that the payload is permanently stored and continues to trigger the behaviour in subsequent sessions.
This differentiates it from other vectors in the catalog where the contaminated input ends up stored in history, activity state, or other persistent structures.
Why is it interesting within STA?
At first glance, a problem limited to the processing associated with a context menu might appear to be simply an application issue.
But from the STA perspective, it is interesting because it shows a recurring characteristic:
An apparently ordinary input can traverse a processing surface without there being a limitation proportional to the cost it can generate.
The goal of STA is not to claim that all documented behaviours have exactly the same technical cause.
The goal is to identify an architectural pattern that appears when structured data traverses different layers of Android and its applications.
Furthermore, the research distinguishes between problems that are specific to an application and those where a framework characteristic can amplify their consequences.
That distinction is fundamental: the fact that a behaviour can propagate through the framework does not automatically mean that the original defect belongs to the framework.
Evidence
STA-002 is classified in the whitepaper as:
Tier B — Behavioral
This means that there is evidence based on observed behaviour, but that for this specific vector there is insufficient low-level evidence to classify it as Tier A.
In particular, STA-002 should not be presented as if a complete native stack trace existed that, by itself, demonstrated the entire causal chain.
This distinction is part of the STA methodology and is important for maintaining a clear separation between:
- observed behaviour;
- inferred mechanism;
- mechanism demonstrated through low-level evidence.
Conceptual mitigation
Mitigation should occur before the data can generate a disproportionate cost.
For this type of surface, the general approach would be:
URL received
│
▼
Size validation
│
├── within limit ──► processing
│
└── outside limit ──► truncate / reject
The idea is not simply to detect specific strings or characters.
Defence must establish reasonable limits on the amount and complexity of data that an operation can process, especially when that operation runs synchronously.
STA-002 within the research map
STA-002 is important not because it is the highest-impact vector, but because it is part of the early observations that helped build the STA model.
Subsequently, vectors with much more severe characteristics appeared:
- persistence;
- state contamination;
- resource exhaustion;
- inter-process interaction;
- impacts on system components;
- and other forms of amplification.
These cases allowed us to study whether the observed behaviours could be understood as completely independent incidents or whether a common pattern existed.
Version v5 of the whitepaper documents 32 vectors within the Structured Text Amplification framework.
Why publish a Tier B vector?
Because the value of research does not depend exclusively on every observation having the same depth of evidence.
STA-002 serves to show how the model began to be constructed.
The fact that the vector has a Tier B classification does not automatically make it irrelevant. It means that the level of certainty must be expressed correctly.
Methodology matters as much as the finding.
Methodological note
STA-002 should not be presented as "an exploit that breaks Android".
It is much more accurate to describe it as:
A case where a structured input can provoke a disproportionate cost during an apparently normal interaction with a link and its context menu.
That formulation reflects the level of available evidence and avoids overstating conclusions that Tier B material does not, by itself, allow us to demonstrate.
And precisely for that reason, STA-002 makes a good starting point for this series.
Not all vectors have the same impact.
Not all have the same mechanism.
Not all have the same level of evidence.
What we are investigating is whether, behind them, a common pattern exists.
Structured Text Amplification
STA-002 is just the second chapter.
As we move through the catalog, vectors with very different mechanisms, surfaces, and impacts will appear.
The question will always be the same:
What happens when an apparently innocuous data item acquires a very different cost as it traverses the layers that process it?
That is the problem that Structured Text Amplification seeks to study.
Whitepaper: Resilience Gaps in Android IPC, SavedState and Text Layout — v6 (August 2026)
📌 About this series
This post is part of a series documenting the 32 vectors of Structured Text Amplification (STA). The aim of the series is to present each vector independently, with its mechanism, impact, and evidence, while maintaining traceability with the complete whitepaper.
Published:
- STA-001 — Context menu (this post)
Next posts (upcoming):
- STA-005 — WhatsApp
- STA-015-DL — Google Drive → SystemUI
- STA-017 — Cross-engine ANR
- STA-027 — Copilot prompt injection
- And more...
Whitepaper: Resilience Gaps in Android IPC, SavedState and Text Layout — v5
Note: To maintain research traceability, each article in this series corresponds to a specific STA identifier and follows the same structure: mechanism, trigger, persistence, evidence, impact, mitigation, and confidence level. This way, the blog functions as a progressive public catalog of the STA research, while the whitepaper remains the consolidated technical reference.
Manuel GarcÃa Peña (Lostmon)
Independent security researcher
lostmon.blogspot.com
