CryptoShield - Automatic On-Device Mitigation for Crypto API Misuse in Android Applications

Florian Draschbacher, Johannes Feichtner · 2023

Misuse of cryptographic APIs remains one of the most common flaws in Android applications. The complexity of cryptographic APIs frequently overwhelms developers. This can lead to mistakes that leak sensitive user data to trivial attacks. Despite herculean efforts by platform provider Google, countermeasures introduced so far were not successful in preventing these flaws. Users remain at risk until an effective systemic mitigation has been found.

Read the paper · More papers on PaperTik