How Safe Is Your Screen? Understanding and Detecting Privacy Leaks in Sensitive Activities
Youngseok Kim, Sungho Lee, Sungjae Hwang
Abstract
Android apps handle sensitive data, often displayed on screens (i.e., Activities), and protecting these activities is vital for ensuring user privacy. Several studies have demonstrated the risk of private data leakage via screen capture and identified malware exploiting this vulnerability. To mitigate such threats, Google introduced FLAG_SECURE, an activity-level security feature that protects an Activity when set by blocking screen capture and restricting display on non-secure devices. Proper usage of this security feature could significantly reduce data leakage risks. However, to the best of our knowledge, its adoption across diverse Android apps has not been systematically studied. In this work, we present a large-scale empirical study of screenshot-based vulnerabilities in Android apps using a systematic static analysis pipeline, ASSA. The pipeline automatically constructs UI models of activities and fragments by leveraging a customized version of Frontmatter, and combines them with a Large Language Model (LLM) to infer runtime context and identify sensitive user data rendered on screens. We apply ASSA to 5,667 popular real-world Android apps and find that 19.8% contain at least one activity that displays sensitive information without screen-capture protection, while 87.2% of apps do not apply FLAG_SECURE to any activity, exposing credentials, financial information, and location data to screenshot attacks. Beyond quantifying prevalence, we analyze FLAG_SECURE usage patterns and establish a taxonomy that captures diverse factors influencing developers’ decisions to adopt or omit screen protection, including intentional privacy protection, intellectual property safeguarding, and unintentional inheritance from base activities. To assess real-world impact, we further conduct in-depth case studies on 200 vulnerable apps and responsibly disclose our findings to the affected vendors, receiving 6 confirmed patches and 20 acknowledgments, including 11 vendors who reported ongoing efforts toward mitigation. These findings indicate that screenshot-based vulnerabilities are not only widespread but also systematically overlooked in practice, highlighting the need for greater awareness and more careful handling of sensitive on-screen information by developers.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get f7ef8315-3740-4e11-9ac2-da628d87dfc1Related papers
- Towards HTTPS Everywhere on Android: We Are Not There YetAndrea Possemato, Yanick FratantonioUSENIX Security 2020
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky et al.S&P 2017 · 293 citations
- Understanding Open Ports in Android Applications: Discovery, Diagnosis, and Security AssessmentDaoyuan Wu, Debin Gao, Rocky K. C. Chang, En He et al.NDSS 2019 · 25 citations
- Secrets Unlocked: Evaluating LLMs for Secrets Detection in Android AppsMarco Alecci, Jordan Samhi, Tegawendé F. Bissyandé, Jacques KleinISSTA 2026
- Uncovering Intent based Leak of Sensitive Data in Android FrameworkHao Zhou, Xiapu Luo, Haoyu Wang, Haipeng CaiCCS 2022 · 9 citations
