Lune

ISSTA2026Top-tier venue

How Safe Is Your Screen? Understanding and Detecting Privacy Leaks in Sensitive Activities

Youngseok Kim, Sungho Lee, Sungjae Hwang

2026Year

Abstract

Android apps handle sensitive data, often displayed on screens (i.e., Activities), and protecting these activities is vital for ensuring user privacy. Several studies have demonstrated the risk of private data leakage via screen capture and identified malware exploiting this vulnerability. To mitigate such threats, Google introduced FLAG_SECURE, an activity-level security feature that protects an Activity when set by blocking screen capture and restricting display on non-secure devices. Proper usage of this security feature could significantly reduce data leakage risks. However, to the best of our knowledge, its adoption across diverse Android apps has not been systematically studied. In this work, we present a large-scale empirical study of screenshot-based vulnerabilities in Android apps using a systematic static analysis pipeline, ASSA. The pipeline automatically constructs UI models of activities and fragments by leveraging a customized version of Frontmatter, and combines them with a Large Language Model (LLM) to infer runtime context and identify sensitive user data rendered on screens. We apply ASSA to 5,667 popular real-world Android apps and find that 19.8% contain at least one activity that displays sensitive information without screen-capture protection, while 87.2% of apps do not apply FLAG_SECURE to any activity, exposing credentials, financial information, and location data to screenshot attacks. Beyond quantifying prevalence, we analyze FLAG_SECURE usage patterns and establish a taxonomy that captures diverse factors influencing developers’ decisions to adopt or omit screen protection, including intentional privacy protection, intellectual property safeguarding, and unintentional inheritance from base activities. To assess real-world impact, we further conduct in-depth case studies on 200 vulnerable apps and responsibly disclose our findings to the affected vendors, receiving 6 confirmed patches and 20 acknowledgments, including 11 vendors who reported ongoing efforts toward mitigation. These findings indicate that screenshot-based vulnerabilities are not only widespread but also systematically overlooked in practice, highlighting the need for greater awareness and more careful handling of sensitive on-screen information by developers.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get f7ef8315-3740-4e11-9ac2-da628d87dfc1

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines