50 ways to leak your data: an exploration of apps’ circumvention of the Android permissions system
https://blog.acolyer.org/2019/09/25/50-ways-to-leak-your-data/ [blog.acolyer.org]
2019-09-25 21:28
This paper is a study of Android apps in the wild that leak permission protected data (identifiers which can be used for tracking, and location information), where those apps should not have been able to see such data due to a lack of granted permissions. By detecting such leakage and analysing the responsible apps, the authors uncover a number of covert and side channels in real-world use.