USENIX Security2026Top-tier venue
Health Hazard, Handle with Care: Investigating the Privacy Risks of Android's Health Connect
Konstantinos Spyridakis, Ioannis Arkalakis, Michalis Diamantaris, Sotiris Ioannidis, Jason Polakis, Panagiotis Ilia
Abstract
Android's Health Connect framework was recently introduced to unify health and fitness data management across apps, promising transparency, user control, and privacy through on-device storage and fine-grained permissions. In this paper, we present the first empirical investigation of Health Connect and show that its design suffers from inherent flaws that introduce serious privacy risks, including the creation of a covert communication channel that can be used to bypass existing access control mechanisms. Accordingly, we use dynamic analysis to systematically examine Health Connect apps, and uncover widespread privacy-invasive behaviors. We find that 60.9% of apps fail to comply with Health Connect's UI data transparency guidelines, and 25.6% do not report the collection or sharing of health records. Additionally, 19.6% of the apps exfiltrate Health Connect data (including records generated by other apps) over the network, combining health information (e.g., blood pressure) with personally identifiable data such as names, emails, Advertising IDs, and phone numbers. These practices violate Google's policies and undermine user expectations of control. We disclosed our findings to Android's Health Connect team, who verified our findings and informed us that our research allowed them to strengthen their review and policy enforcement processes, and take action against bad actors. While this is a step in the right direction, our research demonstrates that Health Connect's design falls short of its stated goals and, ultimately, undermines the privacy protections Android has introduced in recent years.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on16
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 345 citations
- Obfuscation-Resilient Privacy Leak Detection for Mobile Apps Through Differential AnalysisAndrea Continella, Yanick Fratantonio, Martina Lindorfer, Alessandro Puccetti et al.NDSS 2017 · 131 citations
- Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback LoopYanick Fratantonio, Chenxiong Qian, Simon P. Chung, Wenke LeeS&P 2017 · 126 citations
- FLEXDROID: Enforcing In-App Privilege Separation in AndroidJaebaek Seo, Daehyeok Kim, Donghyun Cho, Insik Shin et al.NDSS 2016 · 114 citations
- Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android AppsTrung Tin Nguyen, Michael Backes, Ninja Marnau, Ben StockUSENIX Security 2021 · 70 citations
Related papers
- Wear's my Data? Understanding the Cross-Device Runtime Permission Model in WearablesDoguhan Yeke, Muhammad Ibrahim, Güliz Seray Tuncay, Habiba Farrukh et al.S&P 2024 · 12 citations
- Abandon All Hope Ye Who Enter Here: A Dynamic, Longitudinal Investigation of Android's Data Safety SectionIoannis Arkalakis, Michalis Diamantaris, Serafeim Moustakas, Sotiris Ioannidis et al.USENIX Security 2024 · 13 citations
- Uncovering Intent based Leak of Sensitive Data in Android FrameworkHao Zhou, Xiapu Luo, Haoyu Wang, Haipeng CaiCCS 2022 · 9 citations
- How Android Apps Break the Data Minimization Principle: An Empirical StudyShaokun Zhang, Hanwen Lei, Yuanpeng Wang, Ding Li et al.ASE 2023 · 3 citations
- Hidden in Plain Sight: Exploring Encrypted Channels in Android AppsSajjad Pourali, Nayanamana Samarasinghe, Mohammad MannanCCS 2022 · 5 citations
