"Tap" Without Tapping: A Tag Discovery Forgery Attack on Android NFC
Yilin Li, Jianliang Wu, Chaoshun Zuo, Qingchuan Zhao, Xiaofeng Liu, Xiangpu Song, Chengyu Hu, Shanqing Guo
摘要
Tap-to-X, such as tap-to-pay, which uses an NFC tag tap to trigger the logic flow, is widely used today. Tap-to-X apps treat the tap as proof of user proximity and intent, i.e., the tap is assumed to be intentional and user-aware. On Android, the OS reads data from the tag and eventually dispatches the data to an expected app, yet the security of this post-discovery dispatch process remains under-investigated. In this paper, we analyze Android's post-tap tag dispatch and identify two OS-level design weaknesses that create a semantic origin gap, allowing a local malicious app to mimic a physical tap without any NFC interaction. Exploiting these weaknesses, we develop the tag-dispatch forgery attack (TDFA) and demonstrate that TDFA affects several real-world apps, including Alipay, Huawei AI Life, and Samsung Galaxy Wearable. To measure the impact of TDFA at ecosystem scale, we conduct a largescale analysis of 76,333 Google Play apps, identify 601 potentially affected apps with externally startable RW handlers, and confirm successful forged delivery in 498 of 597 installable and testable apps through on-device validation. We propose an OS-level fix to fundamentally mitigate TDFA and provide suggestions for app developers while the OS-level mitigation is unavailable. We responsibly reported our findings to relevant stakeholders, including the Android Security team, Alipay, and Huawei. They confirmed and acknowledged the corresponding findings and awarded us 300), and ¥ 4,000 (∼$600) as bug bounties, respectively. Google assigned CVE-2026-0081 to the Android vulnerability.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper8
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 被引用 69 次
- Measuring the Insecurity of Mobile Deep Links of AndroidFang Liu, Chun Wang, Andres Pico, Danfeng Yao 等USENIX Security 2017 · 被引用 30 次
- Practical EMV Relay ProtectionAndreea-Ina Radu, Tom Chothia, Christopher J. P. Newton, Ioana Boureanu 等S&P 2022 · 被引用 26 次
- All your app links are belong to us: understanding the threats of instant apps based attacksYutian Tang, Yulei Sui, Haoyu Wang, Xiapu Luo 等FSE 2020 · 被引用 22 次
- Security Analysis and Implementation of Relay-Resistant Contactless PaymentsIoana Boureanu, Tom Chothia, Alexandre Debant, Stéphanie DelauneCCS 2020 · 被引用 10 次
相关 Paper
- Lie to Me: Abusing the Mobile Content Sharing Service for Fun and ProfitGuosheng Xu, Siyi Li, Hao Zhou, Shucen Liu 等WWW 2022 · 被引用 5 次
- Tap 'n Ghost: A Compilation of Novel Attack Techniques against Smartphone TouchscreensSeita Maruyama, Satohiro Wakabayashi, Tatsuya MoriS&P 2019 · 被引用 39 次
- TapTrap: Animation-Driven Tapjacking on AndroidPhilipp Beer, Marco Squarcina, Sebastian Roth, Martina LindorferUSENIX Security 2025
- PHYjacking: Physical Input Hijacking for Zero-Permission Authorization Attacks on AndroidXianbo Wang, Shangcheng Shi, Yikang Chen, Wing Cheong LauNDSS 2022
- Broken Fingers: On the Usage of the Fingerprint API in AndroidAntonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel 等NDSS 2018 · 被引用 33 次
