Call Me Back!: Attacks on System Server and System Apps in Android through Synchronous Callback
Kai Wang, Yuqing Zhang, Peng Liu
Abstract
Android is the most commonly used mobile device operation system. The core of Android, the System Server (SS), is a multi-threaded process that provides most of the system services. Based on a new understanding of the security risks introduced by the callback mechanism in system services, we have discovered a general type of design flaw. A vulnerability detection tool has been designed and implemented based on static taint analysis.We applied the tool on all the 80 system services in the SS of Android 5.1.0. With its help, we have discovered six previously unknown vulnerabilities, which are further confirmed on Android 2.3.7-6.0.1. According to our analysis, about 97.3% of the entire 1.4 billion realworld Android devices are vulnerable. Our proof-of-concept attack proves that the vulnerabilities can enable a malicious app to freeze critical system functionalities or soft-reboot the system immediately. It is a neat type of denial-of-service attack. We also proved that the attacks can be conducted at mission critical moments to achieve meaningful goals, such as anti anti-virus, anti process-killer, hindering app updates or system patching. After being informed, Google confirmed our findings promptly. Several suggestions on how to use callbacks safely are also proposed to Google.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4e326001-f9cd-41ab-b97e-e87e51eb5becCited by top-tier papers3
- Exploit the Last Straw That Breaks Android SystemsLei Zhang, Keke Lian, Haoyu Xiao, Zhibo Zhang et al.S&P 2022 · 10 citations
- NASS: Fuzzing All Native Android System Services with Interface Awareness and CoveragePhilipp Mao, Marcel Busch, Mathias PayerUSENIX Security 2025
- SoK: History Doesn't Repeat Itself, but Android Design-Level Vulnerabilities Rhyme in OpenHarmonyHongkai Chen, Yuqing Yang, Chao Wang, Arpit Nandi et al.USENIX Security 2026
Related papers
- Vulnerable Implicit Service: A RevisitLingguang Lei, Yi He, Kun Sun, Jiwu Jing et al.CCS 2017 · 5 citations
- Statically Discovering High-Order Taint Style Vulnerabilities in OS KernelsHang Zhang, Weiteng Chen, Yu Hao, Guoren Li et al.CCS 2021 · 23 citations
- One Resource to Break Them All: Exploiting Malformed Resources for Permanent Denial-of-Service in AndroidSheng Cao, Hao Zhou, Yanjie Zhao, Tianming Liu et al.CCS 2026
- The Misuse of Android Unix Domain Sockets and Security ImplicationsYuru Shao, Jason Ott, Yunhan Jack Jia, Zhiyun Qian et al.CCS 2016 · 41 citations
- The Doom of Device Drivers: Your Android Device (Most Likely) has N-Day Kernel VulnerabilitiesLukas Maar, Florian Draschbacher, Lorenz Schumm, Ernesto Martínez García et al.USENIX Security 2025
