In pursuit of a secure UI: The cycle of breaking and fixing Android’s UI

Davide Bove, Anatoli Kalysch · it - Information Technology · 2019

Abstract Hijacking user clicks and touch gestures has become a common attack vector and offers a stealthy approach at escalating the privileges of a process without raising red flags among users or AV software. Exploits falling into this category are categorized as clickjacking attacks and have gained increased popularity on mobile devices, Android being the recent victim of a series of UI vulnerabilities. Focusing on the Android OS this paper highlights previous and current UI-based attack vectors and finishes with an overview of security mechanisms, covering both system-wide as well as app-level protection measures.

Read the paper · More papers on PaperTik