WhisperCatcher: Demystifying Unauthorized and Encrypted Private Data Transmission in Android Applications
Zhaoyu Qiu, Ming Fan, Bocan Ma, Yutian Tang, Lei Xue, Haijun Wang, Ting Liu
Abstract
The privacy issues associated with Android apps are increasingly raising our concerns. Unfortunately, a large portion of privacy breaches in Android apps cannot be accurately detected by existing approaches, especially private data that is collected without consent and transmitted in encrypted form. Even if existing studies are able to break the encryption at protocol level to recover the structure and content of traffic packets, they are still unable to understand the code layer encrypted data. To solve this problem, we propose WhisperCatcher, an automated tool for analyzing unauthorized and encrypted private data transmitted by apps. For each app, WhisperCatcher first captures the raw traffic generated during the app’s startup phase, before the user consents to the privacy policy, and then extracts the semantic information. Furthermore, it utilizes the traffic semantics to guide static code analysis and extracts transmission-related key functions. Finally, it performs dynamic instrumentation analysis and recovers the encrypted data, thereby identifying unauthorized private data transmissions. Extensive evaluations show that WhisperCatcher significantly outperforms existing tools, and it achieves the recall of 91.38% and F1-Score of 95.49%, respectively. In addition, we conduct a large-scale measurement analysis on 14,879 apps and WhisperCatcher identifies 13,966 traffic flows from 4,966 apps that transmit private data prior to obtaining user consent, among which 3,838 (27.48%) flows contain app-encrypted data. Our findings highlight the potential privacy leakage risks in Android apps, which should be brought to the attention of the community.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on21
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma et al.NeurIPS 2022 · 22,562 citations
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On et al.USENIX Security 2019 · 196 citations
- TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTimeMingshen Sun, Tao Wei, John C. S. LuiCCS 2016 · 188 citations
- Obfuscation-Resilient Privacy Leak Detection for Mobile Apps Through Differential AnalysisAndrea Continella, Yanick Fratantonio, Martina Lindorfer, Alessandro Puccetti et al.NDSS 2017 · 131 citations
- Things You May Not Know About Android (Un)Packers: A Systematic Study based on Whole-System EmulationYue Duan, Mu Zhang, Abhishek Vasisht Bhaskar, Heng Yin et al.NDSS 2018 · 87 citations
Related papers
- Uncovering Intent based Leak of Sensitive Data in Android FrameworkHao Zhou, Xiapu Luo, Haoyu Wang, Haipeng CaiCCS 2022 · 9 citations
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 20 citations
- WhisperTest: A Voice-Control-based Library for iOS UI AutomationZahra Moti, Tom Janssen-Groesbeek, Steven Monteiro, Andrea Continella et al.CCS 2025
- Ghosts in the Memory: Detecting Unintended Sensitive Data in Android AppsSeonghyeon Song, Taeyoung Kim, Woojoo Kim, Seojin Park et al.ISSTA 2026
- Understanding Worldwide Private Information Collection on AndroidYun Shen, Pierre-Antoine Vervier, Gianluca StringhiniNDSS 2021
