Skip to main navigation Skip to search Skip to main content

Leaky Apps: Targeted Deanonymization on Mobile Phones

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Targeted Deanonymization attacks allow an attacker who controls a website to infer the identity of specific target users browsing that website. They are a severe privacy risk, as they can then be used to carry out highly-Targeted attacks against the inferred identities. These attacks were previously shown to be practical in the desktop environment. In this work, we set to investigate the feasibility of targeted deanonymization in a mobile setting, which presents new opportunities but also new challenges for the attacker. We discover a surprising reality: The attack surface for targeted deanonymization on mobiles is larger than in the desktop setting. We replicate successfully on the Android system all the scenarios that were possible in the desktop setting, and also introduce new attack variants specific to the mobile setting. Notably, the app pop-up variant leverages Android intents to bypass the need for web cookies altogether. We present a decision tree that the attacker can navigate to select the appropriate attack variant, depending on the specific configuration on target user's mobile device. We show that the attacker can target an overwhelming majority of mobile users, including multiple mobile browsers, in-App browsers embedded into common apps, and many resource-sharing services, with attack accuracies and times comparable to those in the desktop setting. We also discuss defenses specific to the mobile setting, ranging from those that can be enabled by users to those that can be deployed by app developers, resource-sharing services, and mobile OS and browser vendors.

Original languageEnglish
Title of host publicationCODASPY 2026 - Proceedings of the 16th ACM Conference on Data and Application Security and Privacy
PublisherAssociation for Computing Machinery, Inc
Pages205-217
Number of pages13
ISBN (Electronic)9798400725623
DOIs
StatePublished - 22 Jun 2026
Event16th ACM Conference on Data and Application Security and Privacy, CODASPY 2026 - Frankfurt am Main, Germany
Duration: 23 Jun 202625 Jun 2026

Publication series

NameCODASPY 2026 - Proceedings of the 16th ACM Conference on Data and Application Security and Privacy

Conference

Conference16th ACM Conference on Data and Application Security and Privacy, CODASPY 2026
Country/TerritoryGermany
CityFrankfurt am Main
Period23/06/2625/06/26

Keywords

  • mobile phones
  • side-channel attacks
  • web privacy

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Computer Science Applications
  • Information Systems
  • Software

Fingerprint

Dive into the research topics of 'Leaky Apps: Targeted Deanonymization on Mobile Phones'. Together they form a unique fingerprint.

Cite this