WinSpy: Cross-window Side-channel Attacks on Android's Multi-window Mode
Zeng Li, Chuan Yan, Liuhuo Wan, Hui Zhuang, Pengfei Hu, Guangdong Bai, Yiran Shen
Abstract
With the development of the Android system and increasing screen size, the use of multi-window mode has become prevalent among users. However, the security and privacy implications associated with this mode have not been thoroughly investigated. This paper uncovers severe and unique security vulnerabilities in Android's multi-window mode, revealing several high-risk side-channels that facilitate diverse cross-window attacks, leading to significant breaches of user privacy. In detail, our research introduces WinSpy, a framework leveraging a newly discovered resource contention side-channel in multi-window mode to fingerprint app launches, web pages, and in-app activities, all without violating Android's permission framework. Our extensive evaluations demonstrate that WinSpy achieves high accuracy (from 70 to 80% detecting website and app launches to over 97% recognizing critical in-app activities). Additionally, we reveal that due to Android's lenient permission management for this mode, window apps can also use Inertial Measurement Unit sensors to launch attacks, such as inferring the user's touch positions outside the window with high precision. Furthermore, we propose systematic mitigations against these vulnerabilities.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Don't Mess with Bro's Cheese! An Empirical Study of Resource Conflict in Android Multi-windowChenkai Guo, Huimin Zhao, Tianhong Wang, Naipeng Dong et al.ASE 2025
- WindowGuard: Systematic Protection of GUI Security in AndroidChuangang Ren, Peng Liu, Sencun ZhuNDSS 2017 · 45 citations
- Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback LoopYanick Fratantonio, Chenxiong Qian, Simon P. Chung, Wenke LeeS&P 2017 · 126 citations
- The Misuse of Android Unix Domain Sockets and Security ImplicationsYuru Shao, Jason Ott, Yunhan Jack Jia, Zhiyun Qian et al.CCS 2016 · 41 citations
- Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context VulnerabilitiesGuangliang Yang, Jeff Huang, Guofei GuUSENIX Security 2019 · 21 citations
