TY - GEN
T1 - Leaky Apps
T2 - 16th ACM Conference on Data and Application Security and Privacy, CODASPY 2026
AU - Blacha, Robert
AU - Oren, Yossi
AU - Curtmola, Reza
N1 - Publisher Copyright:
© 2026 Owner/Author.
PY - 2026/6/22
Y1 - 2026/6/22
N2 - Targeted Deanonymization attacks allow an attacker who controls a website to infer the identity of specific target users browsing that website. They are a severe privacy risk, as they can then be used to carry out highly-Targeted attacks against the inferred identities. These attacks were previously shown to be practical in the desktop environment. In this work, we set to investigate the feasibility of targeted deanonymization in a mobile setting, which presents new opportunities but also new challenges for the attacker. We discover a surprising reality: The attack surface for targeted deanonymization on mobiles is larger than in the desktop setting. We replicate successfully on the Android system all the scenarios that were possible in the desktop setting, and also introduce new attack variants specific to the mobile setting. Notably, the app pop-up variant leverages Android intents to bypass the need for web cookies altogether. We present a decision tree that the attacker can navigate to select the appropriate attack variant, depending on the specific configuration on target user's mobile device. We show that the attacker can target an overwhelming majority of mobile users, including multiple mobile browsers, in-App browsers embedded into common apps, and many resource-sharing services, with attack accuracies and times comparable to those in the desktop setting. We also discuss defenses specific to the mobile setting, ranging from those that can be enabled by users to those that can be deployed by app developers, resource-sharing services, and mobile OS and browser vendors.
AB - Targeted Deanonymization attacks allow an attacker who controls a website to infer the identity of specific target users browsing that website. They are a severe privacy risk, as they can then be used to carry out highly-Targeted attacks against the inferred identities. These attacks were previously shown to be practical in the desktop environment. In this work, we set to investigate the feasibility of targeted deanonymization in a mobile setting, which presents new opportunities but also new challenges for the attacker. We discover a surprising reality: The attack surface for targeted deanonymization on mobiles is larger than in the desktop setting. We replicate successfully on the Android system all the scenarios that were possible in the desktop setting, and also introduce new attack variants specific to the mobile setting. Notably, the app pop-up variant leverages Android intents to bypass the need for web cookies altogether. We present a decision tree that the attacker can navigate to select the appropriate attack variant, depending on the specific configuration on target user's mobile device. We show that the attacker can target an overwhelming majority of mobile users, including multiple mobile browsers, in-App browsers embedded into common apps, and many resource-sharing services, with attack accuracies and times comparable to those in the desktop setting. We also discuss defenses specific to the mobile setting, ranging from those that can be enabled by users to those that can be deployed by app developers, resource-sharing services, and mobile OS and browser vendors.
KW - mobile phones
KW - side-channel attacks
KW - web privacy
UR - https://www.scopus.com/pages/publications/105044230253
U2 - 10.1145/3800506.3803502
DO - 10.1145/3800506.3803502
M3 - Conference contribution
AN - SCOPUS:105044230253
T3 - CODASPY 2026 - Proceedings of the 16th ACM Conference on Data and Application Security and Privacy
SP - 205
EP - 217
BT - CODASPY 2026 - Proceedings of the 16th ACM Conference on Data and Application Security and Privacy
PB - Association for Computing Machinery, Inc
Y2 - 23 June 2026 through 25 June 2026
ER -