USENIX Security2026Top-tier venue
"Tap" Without Tapping: A Tag Discovery Forgery Attack on Android NFC
Yilin Li, Jianliang Wu, Chaoshun Zuo, Qingchuan Zhao, Xiaofeng Liu, Xiangpu Song, Chengyu Hu, Shanqing Guo
Abstract
Tap-to-X, such as tap-to-pay, which uses an NFC tag tap to trigger the logic flow, is widely used today. Tap-to-X apps treat the tap as proof of user proximity and intent, i.e., the tap is assumed to be intentional and user-aware. On Android, the OS reads data from the tag and eventually dispatches the data to an expected app, yet the security of this post-discovery dispatch process remains under-investigated. In this paper, we analyze Android's post-tap tag dispatch and identify two OS-level design weaknesses that create a semantic origin gap, allowing a local malicious app to mimic a physical tap without any NFC interaction. Exploiting these weaknesses, we develop the tag-dispatch forgery attack (TDFA) and demonstrate that TDFA affects several real-world apps, including Alipay, Huawei AI Life, and Samsung Galaxy Wearable. To measure the impact of TDFA at ecosystem scale, we conduct a largescale analysis of 76,333 Google Play apps, identify 601 potentially affected apps with externally startable RW handlers, and confirm successful forged delivery in 498 of 597 installable and testable apps through on-device validation. We propose an OS-level fix to fundamentally mitigate TDFA and provide suggestions for app developers while the OS-level mitigation is unavailable. We responsibly reported our findings to relevant stakeholders, including the Android Security team, Alipay, and Huawei. They confirmed and acknowledged the corresponding findings and awarded us 300), and ¥ 4,000 (∼$600) as bug bounties, respectively. Google assigned CVE-2026-0081 to the Android vulnerability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f54f6bd8-fb34-4e4a-959d-1312f9be612bBuilds on8
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 69 citations
- Measuring the Insecurity of Mobile Deep Links of AndroidFang Liu, Chun Wang, Andres Pico, Danfeng Yao et al.USENIX Security 2017 · 30 citations
- Practical EMV Relay ProtectionAndreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu et al.S&P 2022 · 26 citations
- All your app links are belong to us: understanding the threats of instant apps based attacksYutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo et al.FSE 2020 · 22 citations
- Security Analysis and Implementation of Relay-Resistant Contactless PaymentsIoana Boureanu, Tom Chothia, Alexandre Debant, Stéphanie DelauneCCS 2020 · 10 citations
Related papers
- Lie to Me: Abusing the Mobile Content Sharing Service for Fun and ProfitGuosheng Xu, Siyi Li, Hao Zhou, Shucen Liu et al.WWW 2022 · 5 citations
- Tap 'n Ghost: A Compilation of Novel Attack Techniques against Smartphone TouchscreensSeita Maruyama, Satohiro Wakabayashi, Tatsuya MoriS&P 2019 · 39 citations
- TapTrap: Animation-Driven Tapjacking on AndroidPhilipp Beer, Marco Squarcina, Sebastian Roth, Martina LindorferUSENIX Security 2025
- PHYjacking: Physical Input Hijacking for Zero-Permission Authorization Attacks on AndroidXianbo Wang, Shangcheng Shi, Yikang Chen, Wing Cheong LauNDSS 2022
- Broken Fingers: On the Usage of the Fingerprint API in AndroidAntonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel et al.NDSS 2018 · 33 citations
