You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Issue #529 requested support for specifying an alternative Android browser-history location because the old ChromeHistory ADB module only queried the Google Chrome path.
The V3 work in #716 removed that ADB module. The current built-in AndroidQF modules do not query browser databases, and the Android backup command only parses SMS/MMS. Browser history is mentioned in the broader Android filesystem work tracked by #838, but there is no dedicated implementation issue describing the required browser coverage.
Proposed change
Reintroduce Android browser-history extraction for filesystem or AndroidQF acquisitions that contain browser databases.
Ideally, the implementation should:
discover and parse all supported browser-history databases present in an acquisition, rather than stopping after the first match or supporting only Google Chrome;
support separately validated paths and schemas for Chromium-family browsers such as Chrome, Brave, Edge, Samsung Internet, and Opera;
support non-Chromium browsers such as Firefox through separate schema-aware parsers where evidence and fixtures are available;
retain the originating browser and database path on every result;
process SQLite WAL/SHM sidecars when present;
add extracted visits to the timeline and URL-indicator checks.
Paths should only be added when supported by source code, vendor documentation, or a reproducible acquisition fixture. Package-name substitution alone should not be treated as proof of a path.
Suggested acceptance criteria
A shared browser-history artifact interface with browser-specific parsers where schemas differ.
Every matching database/profile in the input is processed.
Tests cover Chrome and at least one non-Chrome browser using representative SQLite fixtures.
Tests cover multiple databases and attribution of results to their source database.
The command supports an explicitly supplied history database or path.
Background
Issue #529 requested support for specifying an alternative Android browser-history location because the old
ChromeHistoryADB module only queried the Google Chrome path.The V3 work in #716 removed that ADB module. The current built-in AndroidQF modules do not query browser databases, and the Android backup command only parses SMS/MMS. Browser history is mentioned in the broader Android filesystem work tracked by #838, but there is no dedicated implementation issue describing the required browser coverage.
Proposed change
Reintroduce Android browser-history extraction for filesystem or AndroidQF acquisitions that contain browser databases.
Ideally, the implementation should:
Paths should only be added when supported by source code, vendor documentation, or a reproducible acquisition fixture. Package-name substitution alone should not be treated as proof of a path.
Suggested acceptance criteria