Ghosts in the Memory: Detecting Unintended Sensitive Data in Android Apps
Seonghyeon Song, Taeyoung Kim, Woojoo Kim, Seojin Park, Sungjae Hwang, Hyoungshick Kim
Abstract
Android apps often retain sensitive information such as co-users’ data, authentication tokens, and encryption keys in memory, leaving them vulnerable to unauthorized access. Existing dynamic analysis tools struggle to detect such memory-resident leaks because of three fundamental challenges: (i) runtime application self-protection (RASP) and other anti-analysis mechanisms actively detect and block conventional instrumentation;(ii) the semantic gap between high-level data types and their raw memory representations obscures sensitive content; and (iii) the transient nature of memory-resident data causes snapshot-based methods to misscritical exposures. We present Android-MRI, an OS-level analysis tool that embeds tracing directly into the Android kernel to detect unintended sensitive data leakage through memory while remaining invisible to application-layer defenses. Android-MRI provides instruction-granular monitoring to track the propagation of sensitive data in memory, surfacing the full context of unintended persistence. In an evaluation of 50 popular apps (≥1M installs), Android-MRI bypassed 97.6% of RASP protections (vs. 52.4% for Frida) and revealed 17 previously unknown memory disclosures. These included leaks of profile PINs, subscription-only content, and cryptographic keys. 12 vendors confirmed the issues; 4 have patched them, and 3 (Netflix, Smule, and Delivery Express) acknowledged them via bug bounty programs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- NCScope: hardware-assisted analyzer for native code in Android appsHao Zhou, Shuohan Wu, Xiapu Luo, Ting Wang et al.ISSTA 2022 · 16 citations
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 123 citations
- Uncovering Intent based Leak of Sensitive Data in Android FrameworkHao Zhou, Xiapu Luo, Haoyu Wang, Haipeng CaiCCS 2022 · 9 citations
- WhisperCatcher: Demystifying Unauthorized and Encrypted Private Data Transmission in Android ApplicationsZhaoyu Qiu, Ming Fan, Bocan Ma, Yutian Tang et al.ICSE 2026
- How Safe Is Your Screen? Understanding and Detecting Privacy Leaks in Sensitive ActivitiesYoungseok Kim, Sungho Lee, Sungjae HwangISSTA 2026
