Lune

ISSTA2026Top-tier venue

Ghosts in the Memory: Detecting Unintended Sensitive Data in Android Apps

Seonghyeon Song, Taeyoung Kim, Woojoo Kim, Seojin Park, Sungjae Hwang, Hyoungshick Kim

2026Year

Abstract

Android apps often retain sensitive information such as co-users’ data, authentication tokens, and encryption keys in memory, leaving them vulnerable to unauthorized access. Existing dynamic analysis tools struggle to detect such memory-resident leaks because of three fundamental challenges: (i) runtime application self-protection (RASP) and other anti-analysis mechanisms actively detect and block conventional instrumentation;(ii) the semantic gap between high-level data types and their raw memory representations obscures sensitive content; and (iii) the transient nature of memory-resident data causes snapshot-based methods to misscritical exposures. We present Android-MRI, an OS-level analysis tool that embeds tracing directly into the Android kernel to detect unintended sensitive data leakage through memory while remaining invisible to application-layer defenses. Android-MRI provides instruction-granular monitoring to track the propagation of sensitive data in memory, surfacing the full context of unintended persistence. In an evaluation of 50 popular apps (≥1M installs), Android-MRI bypassed 97.6% of RASP protections (vs. 52.4% for Frida) and revealed 17 previously unknown memory disclosures. These included leaks of profile PINs, subscription-only content, and cryptographic keys. 12 vendors confirmed the issues; 4 have patched them, and 3 (Netflix, Smule, and Delivery Express) acknowledged them via bug bounty programs.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines