Risky Cohabitation: Understanding and Addressing Over-privilege Risks of Commodity Application Virtualization Platforms in Android
Part Of
CODASPY 2024 - Proceedings of the 14th ACM Conference on Data and Application Security and Privacy
Journal Volume
2
Start Page
253
End Page
264
ISBN (of the container)
979-840070421-5
Date Issued
2024-06-19
Author(s)
Abstract
The Android system protects its users' privacy via app permissions, which govern apps' access to sensitive data and resources. However, recent research has reported that, during app virtualization, the current Android permission model fails to prevent illegal permission usage: apps can exploit the User ID shared among co-hosted apps in the same virtualized environment to perform unauthorized actions. To the best of our knowledge, such over-privilege issues have not been thoroughly investigated; neither has a practical defense proposed to address them.
Event(s)
14th ACM Conference on Data and Application Security and Privacy, CODASPY 2024
Publisher
ACM
Type
conference paper
