Lock the Door But Keep the Window Open: Extracting App-Protected Accessibility Information from Browser-Rendered Websites
Haichuan Xu, Runze Zhang, Mingxuan Yao, David Oygenblik, Yizhi Huang, Jeman Park, Brendan Saltaformaggio
摘要
The Android accessibility (a11y) service has been widely utilized by malware to abuse benign services. To prevent such abuse, developers need to secure a11y content access in both their apps and mobile websites. However, a misalignment of a11y protection mechanisms exists between them. Prior research has focused on attacking and defending a11y information embedded in native Android apps. However, our research found that a11y malware can retrieve app-protected a11y information in its mobile browser-rendered website counterpart, leaving mobile browser users more vulnerable to a11y attacks than app users. To help benign service developers vet this attack surface, we developed SOMBRA, an automated analysis pipeline to vet browser-side leakage of a11y information that is a11y-protected in apps. Using SOMBRA, we analyzed 294 benign services and found 29 of them deploy app-side a11y protection mechanisms to secure 256 views. SOMBRA discovered that 241, 402, 244, and 251 elements corresponding to their protected app-side views are a11y-exposed in their websites rendered by Chrome, Firefox, Brave, and Edge browsers, respectively. The leaked elements contain sensitive personal identifiable information. Finally, SOMBRA discovered that most developers do not adopt browser-side a11y protections because existing mechanisms either have ineffective protection or hinder the usability of their content.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper24
- FlowFence: Practical Data Protection for Emerging IoT Application FrameworksEarlence Fernandes, Justin Paupore, Amir Rahmati, Daniel Simionato 等USENIX Security 2016 · 被引用 296 次
- Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback LoopYanick Fratantonio, Chenxiong Qian, Simon P. Chung, Wenke LeeS&P 2017 · 被引用 126 次
- Bug Fixes, Improvements, ... and Privacy Leaks - A Longitudinal Study of PII Leaks Across Android App VersionsJingjing Ren, Martina Lindorfer, Daniel J. Dubois, Ashwin Rao 等NDSS 2018 · 被引用 91 次
- Phishing Attacks on Modern AndroidSimone Aonzo, Alessio Merlo, Giulio Tavella, Yanick FratantonioCCS 2018 · 被引用 68 次
- Latte: Use-Case and Assistive-Service Driven Automated Accessibility Testing Framework for AndroidNavid Salehnamadi, Abdulaziz Alshayban, Jun-Wei Lin, Iftekhar Ahmed 等CHI 2021 · 被引用 52 次
相关 Paper
- DVa: Extracting Victims and Abuse Vectors from Android Accessibility MalwareHaichuan Xu, Mingxuan Yao, Runze Zhang, Mohamed Moustafa Dawoud 等USENIX Security 2024 · 被引用 10 次
- A11y and Privacy don't have to be mutually exclusive: Constraining Accessibility Service Misuse on AndroidJie Huang, Michael Backes, Sven BugielUSENIX Security 2021 · 被引用 13 次
- A Comparative Study of Dark Patterns Across Web and Mobile ModalitiesJohanna Gunawan, Amogh Pradeep, David R. Choffnes, Woodrow Hartzog 等CSCW 2021 · 被引用 128 次
- Do Not Give a Dog Bread Every Time He Wags His Tail: Stealing Passwords through Content Queries (CONQUER) AttacksChongqing Lei, Zhen Ling, Yue Zhang, Kai Dong 等NDSS 2023
- "I tend to view ads almost like a pestilence": On the Accessibility Implications of Mobile Ads for Blind UsersZiyao He, Syed Fatiul Huq, Sam MalekICSE 2024 · 被引用 6 次
