USENIX Security2025Top-tier venue
ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade ago
Florian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan Mangard
Abstract
JuiceJacking is an attack in which malicious chargers compromise connected mobile devices. Shortly after the attack was discovered about a decade ago, mobile OSs introduced user prompts for confirming data connections from a USB host to a mobile device. Since the introduction of this countermeasure, no new USB-based attacks with comparable impact have been found.
In this paper, we present a novel family of USB-based attacks on mobile devices, CHOICEJACKING, which is the first to bypass existing JuiceJacking mitigations. We observe that these mitigations assume that an attacker cannot inject input events while establishing a data connection. However, we show that this assumption does not hold in practice. We present a platform-agnostic attack principle and three concrete attack techniques for Android and iOS that allow a malicious charger to autonomously spoof user input to enable its own data connection. Our evaluation using a custom cheap malicious charger design reveals an alarming state of USB security on mobile platforms. Despite vendor customizations in USB stacks, CHOICEJACKING attacks gain access to sensitive user files (pictures, documents, app data) on all tested devices from 8 vendors including the top 6 by market share. For two vendors, our attacks allow file extraction from locked devices. For stealthily performing attacks that require an unlocked device, we use a power line side-channel to detect suitable moments, i.e., when the user does not notice visual artifacts.
We responsibly disclosed all findings to affected vendors. All but one (including Google, Samsung, Xiaomi, and Apple) acknowledged our attacks and are in the process of integrating mitigations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on27
- ECDSA Key Extraction from Mobile Devices via Nonintrusive Physical Side ChannelsDaniel Genkin, Lev Pachmanov, Itamar Pipman, Eran Tromer et al.CCS 2016 · 196 citations
- Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwdMathy Vanhoef, Eyal RonenS&P 2020 · 146 citations
- Users Really Do Plug in USB Drives They FindMatthew Tischer, Zakir Durumeric, Sam Foster, Sunny Duan et al.S&P 2016 · 97 citations
- Charger-Surfing: Exploiting a Power Line Side-Channel for Smartphone Information LeakagePatrick Cronin, Xing Gao, Chengmo Yang, Haining WangUSENIX Security 2021 · 62 citations
- A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct LinkMilan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich et al.USENIX Security 2019 · 59 citations
Related papers
- XPorter: A Study of the Multi-Port Charger Security on Privacy Leakage and Voice InjectionTao Ni, Yongliang Chen, Weitao Xu, Lei Xue et al.MobiCom 2023 · 15 citations
- Fast or Secure? Push the Limit of Privacy Leakage Threat via Charging Side-Channel AttacksJiaxin Jiang, Xutong Zhang, Jiahao Li, Leqi Zhao et al.WWW 2026
- FuzzUSB: Hybrid Stateful Fuzzing of USB Gadget StacksKyungtae Kim, Taegyu Kim, Ertza Warraich, Byoungyoung Lee et al.S&P 2022 · 32 citations
- PHYjacking: Physical Input Hijacking for Zero-Permission Authorization Attacks on AndroidXianbo Wang, Shangcheng Shi, Yikang Chen, Wing Cheong LauNDSS 2022
- WIGHT: Wired Ghost Touch Attack on Capacitive TouchscreensYan Jiang, Xiaoyu Ji, Kai Wang, Chen Yan et al.S&P 2022 · 23 citations
