Android Custom Permissions Demystified: From Privilege Escalation to Design Shortcomings
Rui Li, Wenrui Diao, Zhou Li, Jianqi Du, Shanqing Guo
Abstract
Permission is the fundamental security mechanism for protecting user data and privacy on Android. Given its importance, security researchers have studied the design and usage of permissions from various aspects. However, most of the previous research focused on the security issues of system permissions. Overlooked by many researchers, an app can use custom permissions to share its resources and capabilities with other apps. However, the security implications of using custom permissions have not been fully understood. In this paper, we systematically evaluate the design and implementation of Android custom permissions. Notably, we built an automatic fuzzing tool, called CUPERFUZZER, to detect custom permissions related vulnerabilities existing in the Android OS. CUPERFUZZER treats the operations of the permission mechanism as a black-box and executes massive targeted test cases to trigger privilege escalation. In the experiments, CUPERFUZZER discovered 2,384 effective cases with 30 critical paths successfully. Through investigating these vulnerable cases and analyzing the source code of Android OS, we further identified a series of severe design shortcomings lying in the Android permission framework, including dangling custom permission, inconsistent permissiongroup mapping, custom permission elevating, and inconsistent permission definition. Exploiting any of these shortcomings, a malicious app can obtain dangerous system permissions without user consent and further access unauthorized platform resources. On top of these observations, we propose some general design guidelines to secure custom permissions. Our findings have been acknowledged by the Android security team and rated as High severity.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5dc48d84-9069-44ff-ad34-d975bd15566bCited by top-tier papers10
- Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party ApplicationsNanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu et al.CCS 2023 · 15 citations
- AmpereBleed: Exploiting On-chip Current Sensors for Circuit-Free Attacks on ARM-FPGA SoCsXin Zhang, Yi Yang, Jiajun Zou, Qingni Shen et al.DAC 2025 · 2 citations
- On the (In)Security of Non-resettable Device Identifiers in Custom Android SystemsZikan Dong, Liu Wang, Guoai Xu, Haoyu WangASE 2025 · 1 citation
- Ariadne: Navigating through the Labyrinth of Data-Driven Customization Inconsistencies in AndroidParjanya Vyas, Haseeb Ur Rehman Faheem, Yousra Aafer, N. AsokanUSENIX Security 2025
- Lost in Conversion: Exploit Data Structure Conversion with Attribute Loss to Break Android SystemsRui Li, Wenrui Diao, Shishuai Yang, Xiangyu Liu et al.USENIX Security 2023
Builds on4
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel et al.USENIX Security 2016 · 161 citations
- Resolving the Predicament of Android Custom PermissionsGüliz Seray Tuncay, Soteris Demetriou, Karan Ganju, Carl A. GunterNDSS 2018 · 51 citations
- DroidCap: OS Support for Capability-based Permissions in AndroidAbdallah Dawoud, Sven BugielNDSS 2019 · 17 citations
- See No Evil: Phishing for Permissions with False TransparencyGüliz Seray Tuncay, Jingyu Qian, Carl A. GunterUSENIX Security 2020
Related papers
- Exploit the Last Straw That Breaks Android SystemsLei Zhang, Keke Lian, Haoyu Xiao, Zhibo Zhang et al.S&P 2022 · 10 citations
- MALintent: Coverage Guided Intent Fuzzing Framework for AndroidAmmar Askar, Fabian Fleischer, Christopher Kruegel, Giovanni Vigna et al.NDSS 2025
- Born with a Silver Spoon: On the (In)Security of Native Granted App Privileges in Custom Android ROMsChao Wang, Yanjie Zhao, Jiapeng Deng, Haoyu WangS&P 2025
- APER: Evolution-Aware Runtime Permission Misuse Detection for Android AppsSinan Wang, Yibo Wang, Xian Zhan, Ying Wang et al.ICSE 2022 · 19 citations
- Uncovering Intent based Leak of Sensitive Data in Android FrameworkHao Zhou, Xiapu Luo, Haoyu Wang, Haipeng CaiCCS 2022 · 9 citations
