CryptoShield - Automatic On-Device Mitigation for Crypto API Misuse in Android Applications
Florian Draschbacher, Johannes Feichtner · 2023
Misuse of cryptographic APIs remains one of the most common flaws in Android applications. The complexity of cryptographic APIs frequently overwhelms developers. This can lead to mistakes that leak sensitive user data to trivial attacks. Despite herculean efforts by platform provider Google, countermeasures introduced so far were not successful in preventing these flaws. Users remain at risk until an effective systemic mitigation has been found.