Hybrid application frameworks introduce new browser APIs that let Web applications access native resources on mobile devices. We analyze inconsistencies between access control policies at different levels of the hybrid software stack, demonstrate how they expose native resources to malicious Web content, and propose a defense.