ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade ago
Florian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan Mangard
摘要
JuiceJacking is an attack in which malicious chargers compromise connected mobile devices. Shortly after the attack was discovered about a decade ago, mobile OSs introduced user prompts for confirming data connections from a USB host to a mobile device. Since the introduction of this countermeasure, no new USB-based attacks with comparable impact have been found.
In this paper, we present a novel family of USB-based attacks on mobile devices, CHOICEJACKING, which is the first to bypass existing JuiceJacking mitigations. We observe that these mitigations assume that an attacker cannot inject input events while establishing a data connection. However, we show that this assumption does not hold in practice. We present a platform-agnostic attack principle and three concrete attack techniques for Android and iOS that allow a malicious charger to autonomously spoof user input to enable its own data connection. Our evaluation using a custom cheap malicious charger design reveals an alarming state of USB security on mobile platforms. Despite vendor customizations in USB stacks, CHOICEJACKING attacks gain access to sensitive user files (pictures, documents, app data) on all tested devices from 8 vendors including the top 6 by market share. For two vendors, our attacks allow file extraction from locked devices. For stealthily performing attacks that require an unlocked device, we use a power line side-channel to detect suitable moments, i.e., when the user does not notice visual artifacts.
We responsibly disclosed all findings to affected vendors. All but one (including Google, Samsung, Xiaomi, and Apple) acknowledged our attacks and are in the process of integrating mitigations.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper27
- ECDSA Key Extraction from Mobile Devices via Nonintrusive Physical Side ChannelsDaniel Genkin, Lev Pachmanov, Itamar Pipman, Eran Tromer 等CCS 2016 · 被引用 196 次
- Dragonblood: Analyzing the Dragonfly Handshake of WPA3 and EAP-pwdMathy Vanhoef, Eyal RonenS&P 2020 · 被引用 146 次
- Users Really Do Plug in USB Drives They FindMatthew Tischer, Zakir Durumeric, Sam Foster, Sunny Duan 等S&P 2016 · 被引用 97 次
- Charger-Surfing: Exploiting a Power Line Side-Channel for Smartphone Information LeakagePatrick Cronin, Xing Gao, Chengmo Yang, Haining WangUSENIX Security 2021 · 被引用 62 次
- A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct LinkMilan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich 等USENIX Security 2019 · 被引用 59 次
相关 Paper
- XPorter: A Study of the Multi-Port Charger Security on Privacy Leakage and Voice InjectionTao Ni, Yongliang Chen, Weitao Xu, Lei Xue 等MobiCom 2023 · 被引用 15 次
- Fast or Secure? Push the Limit of Privacy Leakage Threat via Charging Side-Channel AttacksJiaxin Jiang, Xutong Zhang, Jiahao Li, Leqi Zhao 等WWW 2026
- FuzzUSB: Hybrid Stateful Fuzzing of USB Gadget StacksKyungtae Kim, Taegyu Kim, Ertza Warraich, Byoungyoung Lee 等S&P 2022 · 被引用 32 次
- PHYjacking: Physical Input Hijacking for Zero-Permission Authorization Attacks on AndroidXianbo Wang, Shangcheng Shi, Yikang Chen, Wing Cheong LauNDSS 2022
- WIGHT: Wired Ghost Touch Attack on Capacitive TouchscreensYan Jiang, Xiaoyu Ji, Kai Wang, Chen Yan 等S&P 2022 · 被引用 23 次
