PHYjacking: Physical Input Hijacking for Zero-Permission Authorization Attacks on Android
Xianbo Wang, Shangcheng Shi, Yikang Chen, Wing Cheong Lau
Abstract
—Nowadays, most mobile devices are equipped with various hardware interfaces such as touchscreen, fingerprint scanner, camera and microphone to capture inputs from the user. Many mobile apps use these physical interfaces to receive user-input for authentication/authorization operations including one-click login, fingerprint-based payment approval, and face/voice unlocking. In this paper, we investigate the so-called PHYjacking attack where a victim is misled by a zero-permission malicious app to feed physical inputs to different hardware interfaces on a mobile device to result in unintended authorization. We analyze the protection mechanisms in Android for different types of physical input interfaces and introduce new techniques to bypass them. Specifically, we identify weaknesses in the existing protection schemes for the related system APIs and observe common pitfalls when apps implement physical-input-based authorization. Worse still, we discover a race-condition bug in Android that can be exploited even when app-based mitigations are properly implemented. Based on these findings, we introduce fingerprint-jacking and facejacking techniques and demonstrate their impact on real apps. We also discuss the feasibility of launching similar attacks against NFC and microphone inputs, as well as effective tapjacking attacks against Single Sign-On apps. We have designed a static analyzer to examine 3000+ real-world apps and find 44% of them contain PHYjacking-related implementation flaws. We demonstrate the practicality and potential impact of PHYjacking via proof-of-concept implementations which enable unauthorized money transfer on a payment app with over 800 million users, user-privacy leak from a social media app with over 400 million users and escalating app permissions in Android 11.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- An Empirical Study on Fingerprint API Misuse with Lifecycle Analysis in Real-world Android AppsXin Zhang, Xiaohan Zhang, Zhichen Liu, Bo Zhao et al.NDSS 2025
- SoK: History Doesn't Repeat Itself, but Android Design-Level Vulnerabilities Rhyme in OpenHarmonyHongkai Chen, Yuqing Yang, Chao Wang, Arpit Nandi et al.USENIX Security 2026
- TapTrap: Animation-Driven Tapjacking on AndroidPhilipp Beer, Marco Squarcina, Sebastian Roth, Martina LindorferUSENIX Security 2025
- Mind the Gap: Action Rebinding Attacks against Android GUI AgentsYi Qian, Kunwei Qian, Xingbang He, Ligeng Chen et al.CCS 2026
Builds on8
- Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback LoopYanick Fratantonio, Chenxiong Qian, Simon P. Chung, Wenke LeeS&P 2017 · 126 citations
- Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViewsTongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen et al.CCS 2017 · 47 citations
- WindowGuard: Systematic Protection of GUI Security in AndroidChuangang Ren, Peng Liu, Sencun ZhuNDSS 2017 · 45 citations
- AWare: Preventing Abuse of Privacy-Sensitive Sensors via Operation BindingsGiuseppe Petracca, Ahmad Atamli-Reineh, Yuqiong Sun, Jens Grossklags et al.USENIX Security 2017 · 35 citations
- Broken Fingers: On the Usage of the Fingerprint API in AndroidAntonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel et al.NDSS 2018 · 33 citations
Related papers
- Beyond the Surface: Uncovering the Unprotected Components of Android Against Overlay AttackHao Zhou, Shuohan Wu, Chenxiong Qian, Xiapu Luo et al.NDSS 2024
- ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade agoFlorian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan MangardUSENIX Security 2025
- Foot in the Door: Uncovering the Multi-Step Authorization Exploitation in Mobile ApplicationsYizhe Shi, Zhemin Yang, Qiaodan Hou, Lukai Cui et al.CCS 2026
- "Tap" Without Tapping: A Tag Discovery Forgery Attack on Android NFCYilin Li, Jianliang Wu, Chaoshun Zuo, Qingchuan Zhao et al.USENIX Security 2026
- No Pardon for the Interruption: New Inference Attacks on Android Through Interrupt Timing AnalysisWenrui Diao, Xiangyu Liu, Zhou Li, Kehuan ZhangS&P 2016 · 79 citations
