Lost in Conversion: Exploit Data Structure Conversion with Attribute Loss to Break Android Systems
Rui Li, Wenrui Diao, Shishuai Yang, Xiangyu Liu, Shanqing Guo, Kehuan Zhang
摘要
Inside the operating system, the processing of configuration files tends to be complicated and involves various data operation procedures. On Android, the processing of manifest files (the principal configuration files of Android apps) correlates to multiple core system mechanisms, such as permission and component management. It is widely recognized that improperly configured manifest files can put apps at risk. Even worse, we find that vulnerable configuration data processing can be exploited by crafted manifest files to break the Android system mechanisms, even achieving privilege escalation. In this work, we systematically studied the Android manifest processing procedures and discovered a new category of vulnerabilities called the Evil Twins flaw. In brief, during the processing of twin manifest elements (with the same name but different attributes), the ill-considered data structure conversion (e.g., from List to Map without considering the duplication issue) merges them into one item with attribute loss, further resulting in system configuration inconsistency, i.e., potential security risks. To detect the Evil Twins flaw lying in the Android OS, we designed an automated analysis tool, TWINDROID, to identify the data structure conversions with attribute loss and then manually confirm the vulnerabilities. With TWINDROID, we assessed the code of AOSP Android 11 & 12. Finally, 47 suspicious methods were reported, and four vulnerabilities were identified, which can be exploited to achieve permission escalation and revoking prevention. All discovered vulnerabilities have been acknowledged by Google, and three CVE IDs have been assigned.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Lost in Migration: Exposing Android Framework Vulnerabilities in Parallel Java-Kotlin ImplementationsRui Li, Wenrui Diao, Debin GaoCCS 2026
- SoK: History Doesn't Repeat Itself, but Android Design-Level Vulnerabilities Rhyme in OpenHarmonyHongkai Chen, Yuqing Yang, Chao Wang, Arpit Nandi 等USENIX Security 2026
它引用的顶会 Paper5
- Resolving the Predicament of Android Custom PermissionsGüliz Seray Tuncay, Soteris Demetriou, Karan Ganju, Carl A. GunterNDSS 2018 · 被引用 51 次
- Harvesting Inconsistent Security Configurations in Custom Android ROMs via Differential AnalysisYousra Aafer, Xiao Zhang, Wenliang DuUSENIX Security 2016 · 被引用 43 次
- Android Custom Permissions Demystified: From Privilege Escalation to Design ShortcomingsRui Li, Wenrui Diao, Zhou Li, Jianqi Du 等S&P 2021 · 被引用 32 次
- Invetter: Locating Insecure Input Validations in Android ServicesLei Zhang, Zhemin Yang, Yuyu He, Zhenyu Zhang 等CCS 2018 · 被引用 30 次
- Dissecting Residual APIs in Custom Android ROMsZeinab El-Rewini, Yousra AaferCCS 2021 · 被引用 8 次
相关 Paper
- Parcel Mismatch Demystified: Addressing a Decade-Old Security Challenge in AndroidSheng Cao, Hao Zhou, Songzhou Shi, Yanjie Zhao 等CCS 2025
- Detecting and Measuring Misconfigured Manifests in Android AppsYuqing Yang, Mohamed Elsabagh, Chaoshun Zuo, Ryan Johnson 等CCS 2022 · 被引用 11 次
- Born with a Silver Spoon: On the (In)Security of Native Granted App Privileges in Custom Android ROMsChao Wang, Yanjie Zhao, Jiapeng Deng, Haoyu WangS&P 2025
- The Misuse of Android Unix Domain Sockets and Security ImplicationsYuru Shao, Jason Ott, Yunhan Jack Jia, Zhiyun Qian 等CCS 2016 · 被引用 41 次
- Call Me Back!: Attacks on System Server and System Apps in Android through Synchronous CallbackKai Wang, Yuqing Zhang, Peng LiuCCS 2016 · 被引用 22 次
