Uncovering Intent based Leak of Sensitive Data in Android Framework
Hao Zhou, Xiapu Luo, Haoyu Wang, Haipeng Cai
Abstract
To prevent unauthorized apps from retrieving the sensitive data, Android framework enforces a permission based access control. However, it has long been known that, to bypass the access control, unauthorized apps can intercept the Intent objects which are sent by authorized apps and carry the retrieved sensitive data. We find that there is a new (previously unknown) attack surface in Android framework that can be exploited by unauthorized apps to violate the access control. Specifically, we discover that part of Intent objects that are sent by Android framework and carry sensitive data can be received by unauthorized apps, resulting in the leak of sensitive data. In this paper, we conduct the first systematic investigation on the new attack surface namely the Intent based leak of sensitive data in Android framework. To automatically uncover such kind of vulnerability in Android framework, we design and develop a new tool named LeakDetector, which finds the Intent objects sent by Android framework that can be received by unauthorized apps and carry the sensitive data. Applying LeakDetector to 10 commercial Android systems, we find that it can effectively uncover the Intent based leak of sensitive data in Android framework. Specifically, we discover 36 exploitable cases of such kind of data leak, which can be abused by unauthorized apps to steal the sensitive data, violating the access control. At the time of writing, 16 of them have been confirmed by Google, Samsung, and Xiaomi, and we received bug bounty rewards from these mobile vendors. CCS CONCEPTS • Security and privacy → Mobile platform security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5bca8263-2ca7-4495-b896-acca961e66e9Cited by top-tier papers4
- On the (In)Security of Non-resettable Device Identifiers in Custom Android SystemsZikan Dong, Liu Wang, Guoai Xu, Haoyu WangASE 2025 · 1 citation
- Ariadne: Navigating through the Labyrinth of Data-Driven Customization Inconsistencies in AndroidParjanya Vyas, Haseeb Ur Rehman Faheem, Yousra Aafer, N. AsokanUSENIX Security 2025
- SoK: History Doesn't Repeat Itself, but Android Design-Level Vulnerabilities Rhyme in OpenHarmonyHongkai Chen, Yuqing Yang, Chao Wang, Arpit Nandi et al.USENIX Security 2026
- Beyond the Surface: Uncovering the Unprotected Components of Android Against Overlay AttackHao Zhou, Shuohan Wu, Chenxiong Qian, Xiapu Luo et al.NDSS 2024
Builds on12
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On et al.USENIX Security 2019 · 196 citations
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel et al.USENIX Security 2016 · 161 citations
- AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency DetectionYousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang et al.NDSS 2018 · 95 citations
- Kratos: Discovering Inconsistent Security Policy Enforcement in the Android FrameworkYuru Shao, Qi Alfred Chen, Zhuoqing Morley Mao, Jason Ott et al.NDSS 2016 · 85 citations
- Malton: Towards On-Device Non-Invasive Mobile Malware Analysis for ARTLei Xue, Yajin Zhou, Ting Chen, Xiapu Luo et al.USENIX Security 2017 · 81 citations
Related papers
- Automated Repair of Information Flow Security in Android Implicit Inter-App CommunicationAbhishek Tiwari, Jyoti Prakash, Zhen Dong, Carlo A. FuriaFM 2024
- Uncovering Cross-Context Inconsistent Access Control Enforcement in AndroidHao Zhou, Haoyu Wang, Xiapu Luo, Ting Chen et al.NDSS 2022
- MALintent: Coverage Guided Intent Fuzzing Framework for AndroidAmmar Askar, Fabian Fleischer, Christopher Kruegel, Giovanni Vigna et al.NDSS 2025
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 123 citations
- This Sneaky Piggy Went to the Android Ad Market: Misusing Mobile Sensors for Stealthy Data ExfiltrationMichalis Diamantaris, Serafeim Moustakas, Lichao Sun, Sotiris Ioannidis et al.CCS 2021 · 8 citations
