Lock the Door But Keep the Window Open: Extracting App-Protected Accessibility Information from Browser-Rendered Websites
Haichuan Xu, Runze Zhang, Mingxuan Yao, David Oygenblik, Yizhi Huang, Jeman Park, Brendan Saltaformaggio
Abstract
The Android accessibility (a11y) service has been widely utilized by malware to abuse benign services. To prevent such abuse, developers need to secure a11y content access in both their apps and mobile websites. However, a misalignment of a11y protection mechanisms exists between them. Prior research has focused on attacking and defending a11y information embedded in native Android apps. However, our research found that a11y malware can retrieve app-protected a11y information in its mobile browser-rendered website counterpart, leaving mobile browser users more vulnerable to a11y attacks than app users. To help benign service developers vet this attack surface, we developed SOMBRA, an automated analysis pipeline to vet browser-side leakage of a11y information that is a11y-protected in apps. Using SOMBRA, we analyzed 294 benign services and found 29 of them deploy app-side a11y protection mechanisms to secure 256 views. SOMBRA discovered that 241, 402, 244, and 251 elements corresponding to their protected app-side views are a11y-exposed in their websites rendered by Chrome, Firefox, Brave, and Edge browsers, respectively. The leaked elements contain sensitive personal identifiable information. Finally, SOMBRA discovered that most developers do not adopt browser-side a11y protections because existing mechanisms either have ineffective protection or hinder the usability of their content.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 54ae29cc-319c-4126-97c3-9efcd948aed6Builds on24
- FlowFence: Practical Data Protection for Emerging IoT Application FrameworksEarlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato et al.USENIX Security 2016 · 296 citations
- Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback LoopYanick Fratantonio, Chenxiong Qian, Simon P. Chung, Wenke LeeS&P 2017 · 126 citations
- Bug Fixes, Improvements, ... and Privacy Leaks - A Longitudinal Study of PII Leaks Across Android App VersionsJingjing Ren, Martina Lindorfer, Daniel J. Dubois, Ashwin Rao et al.NDSS 2018 · 91 citations
- Phishing Attacks on Modern AndroidSimone Aonzo, Alessio Merlo, Giulio Tavella, Yanick FratantonioCCS 2018 · 68 citations
- Latte: Use-Case and Assistive-Service Driven Automated Accessibility Testing Framework for AndroidNavid Salehnamadi, Abdulaziz Alshayban, Jun-Wei Lin, Iftekhar Ahmed et al.CHI 2021 · 52 citations
Related papers
- DVa: Extracting Victims and Abuse Vectors from Android Accessibility MalwareHaichuan Xu, Mingxuan Yao, Runze Zhang, Mohamed Moustafa Dawoud et al.USENIX Security 2024 · 10 citations
- A11y and Privacy don't have to be mutually exclusive: Constraining Accessibility Service Misuse on AndroidJie Huang, Michael Backes, Sven BugielUSENIX Security 2021 · 13 citations
- A Comparative Study of Dark Patterns Across Web and Mobile ModalitiesJohanna Gunawan, Amogh Pradeep, David R. Choffnes, Woodrow Hartzog et al.CSCW 2021 · 128 citations
- Do Not Give a Dog Bread Every Time He Wags His Tail: Stealing Passwords through Content Queries (CONQUER) AttacksChongqing Lei, Zhen Ling, Yue Zhang, Kai Dong et al.NDSS 2023
- "I tend to view ads almost like a pestilence": On the Accessibility Implications of Mobile Ads for Blind UsersZiyao He, Syed Fatiul Huq, Sam MalekICSE 2024 · 6 citations
