USENIX Security2024Top-tier venue
Exploring Covert Third-party Identifiers through External Storage in the Android New Era
Zikan Dong, Tianming Liu, Jiapeng Deng, Haoyu Wang, Li Li, Minghui Yang, Meng Wang, Guosheng Xu, Guoai Xu
Abstract
Third-party tracking plays a vital role in the mobile app ecosystem, which relies on identifiers to gather user data across multiple apps. In the early days of Android, tracking SDKs could effortlessly access non-resettable hardware identifiers for third-party tracking. However, as privacy concerns mounted, Google has progressively restricted device identifier usage through Android system updates. In the new era, tracking SDKs are only allowed to employ user-resettable identifiers which users can also opt out of, prompting SDKs to seek alternative methods for reliable user identification across apps. In this paper, we systematically explore the practice of third-party tracking SDKs covertly storing their own generated identifiers on external storage, thereby circumventing Android's identifier usage restriction and posing a considerable threat to user privacy. We devise an analysis pipeline for an extensive large-scale investigation of this phenomenon, leveraging kernel-level instrumentation and UI testing techniques to automate the recording of app file operations at runtime. Applying our pipeline to 8,000 Android apps, we identified 17 third-party tracking SDKs that store identifiers on external storage. Our analysis reveals that these SDKs employ a range of storage techniques, including hidden files and attaching to existing media files, to make their identifiers more discreet and persistent. We also found that most SDKs lack adequate security measures, compromising the confidentiality and integrity of identifiers and enabling deliberate attacks. Furthermore, we examined the impact of Scoped Storage -Android's latest defense mechanism for external storage on these covert third-party identifiers, and proposed a viable exploit that breaches such a defense mechanism. Our work underscores the need for greater scrutiny of third-party tracking practices and better solutions to safeguard user privacy in the Android ecosystem.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Cross-Boundary Mobile Tracking: Exploring Java-to-JavaScript Information Diffusion in WebViewsSohom Datta, Michalis Diamantaris, Ahsan Zafar, Junhua Su et al.NDSS 2026 · 2 citations
- Intent-aware Fuzzing for Android Hardened ApplicationSeongyun Jeong, Minseong Choi, Haehyun Cho, Seokwoo Choi et al.CCS 2025 · 1 citation
- ScopeVerif: Analyzing the Security of Android's Scoped Storage via Differential AnalysisZeyu Lei, Güliz Seray Tuncay, Beatrice Carissa Williem, Z. Berkay Celik et al.NDSS 2025
- I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-appsYifeng Cai, Ziqi Zhang, Mengyu Yao, Junlin Liu et al.USENIX Security 2025
- SoK: History Doesn't Repeat Itself, but Android Design-Level Vulnerabilities Rhyme in OpenHarmonyHongkai Chen, Yuqing Yang, Chao Wang, Arpit Nandi et al.USENIX Security 2026
Builds on6
- Things You May Not Know About Android (Un)Packers: A Systematic Study based on Whole-System EmulationYue Duan, Mu Zhang, Abhishek Vasisht Bhaskar, Heng Yin et al.NDSS 2018 · 87 citations
- The Price of Free: Privacy Leakage in Personalized Mobile In-Apps AdsWei Meng, Ren Ding, Simon P. Chung, Steven Han et al.NDSS 2016 · 84 citations
- Watching You Watch: The Tracking Ecosystem of Over-the-Top TV Streaming DevicesHooman Mohajeri Moghaddam, Gunes Acar, Ben Burgess, Arunesh Mathur et al.CCS 2019 · 84 citations
- Algebraic-datatype taint tracking, with applications to understanding Android identifier leaksSydur Rahaman, Iulian Neamtiu, Xin YinFSE 2021 · 3 citations
- Cart-ology: Intercepting Targeted Advertising via Ad Network Identity EntanglementChangSeok Oh, Chris Kanich, Damon McCoy, Paul PearceCCS 2022 · 1 citation
Related papers
- On the (In)Security of Non-resettable Device Identifiers in Custom Android SystemsZikan Dong, Liu Wang, Guoai Xu, Haoyu WangASE 2025 · 1 citation
- Fingerprinting SDKs for Mobile Apps and Where to Find Them: Understanding the Market for Device FingerprintingMichael A. Specter, Mihai Christodorescu, Abbie Farr, Bo Ma et al.CCS 2025
- Post-GDPR Threat Hunting on Android Phones: Dissecting OS-level Safeguards of User-unresettable IdentifiersMark Huasong Meng, Qing Zhang, Guangshuai Xia, Yuwei Zheng et al.NDSS 2023
- PolyScope: Multi-Policy Access Control Analysis to Compute Authorized Attack Operations in Android SystemsYu Tsung Lee, William Enck, Haining Chen, Hayawardh Vijayakumar et al.USENIX Security 2021 · 17 citations
- Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKsYifan Zhang, Zhaojie Hu, Xueqiang Wang, Yuhui Hong et al.USENIX Security 2024 · 3 citations
