<div class="csl-bib-body">
<div class="csl-entry">Beer, P., Squarcina, M., Roth, S., & Lindorfer, M. (2025). TapTrap: animation-driven tapjacking on android. In <i>SEC ’25: Proceedings of the 34th USENIX Security Symposium</i> (pp. 3317–3335). USENIX Association.</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/222619
-
dc.description.abstract
Users interact with mobile devices under the assumption that the graphical user interface (GUI) accurately reflects their actions, a trust fundamental to the user experience. In this work, we present TapTrap, a novel attack that enables zero-permission apps to exploit UI animations to undermine this trust relationship. TapTrap can be used by a malicious app to stealthily bypass Android's permission system and gain access to sensitive data or execute destructive actions, such as wiping the device without user approval. Its impact extends beyond the Android ecosystem, enabling tapjacking and Web clickjacking. TapTrap is able to bypass existing tapjacking defenses, as those are targeted toward overlays. Our novel approach, instead, abuses activity transition animations and is effective even on Android 15. We analyzed 99,705 apps from the Play Store to assess whether TapTrap is actively exploited in the wild. Our analysis found no evidence of such exploitation. Additionally, we conducted a large-scale study on these apps and discovered that 76.3% of apps are vulnerable to TapTrap. Finally, we evaluated the real-world feasibility of TapTrap through a user study with 20 participants, showing that all of them failed to notice at least one attack variant. Our findings have resulted in two assigned CVEs.
en
dc.description.sponsorship
WWTF Wiener Wissenschafts-, Forschu und Technologiefonds
-
dc.language.iso
en
-
dc.subject
tapjacking
en
dc.subject
clickjacking
en
dc.subject
android security
en
dc.subject
UI security
en
dc.title
TapTrap: animation-driven tapjacking on android
en
dc.type
Inproceedings
en
dc.type
Konferenzbeitrag
de
dc.contributor.affiliation
University of Bayreuth, Germany
-
dc.relation.isbn
978-1-939133-52-6
-
dc.description.startpage
3317
-
dc.description.endpage
3335
-
dc.relation.grantno
ICT22-060
-
dc.type.category
Full-Paper Contribution
-
tuw.booktitle
SEC '25: Proceedings of the 34th USENIX Security Symposium
-
tuw.relation.publisher
USENIX Association
-
tuw.relation.publisherplace
CA, USA
-
tuw.project.title
Fixing the Broken Bridge Between Mobile Apps and the Web
-
tuw.researchTopic.id
I1
-
tuw.researchTopic.id
I4
-
tuw.researchTopic.name
Logic and Computation
-
tuw.researchTopic.name
Information Systems Engineering
-
tuw.researchTopic.value
60
-
tuw.researchTopic.value
40
-
tuw.publication.orgunit
E192-06 - Forschungsbereich Security and Privacy
-
dc.description.numberOfPages
19
-
tuw.author.orcid
0009-0009-6923-0027
-
tuw.author.orcid
0000-0002-3105-0903
-
tuw.author.orcid
0009-0004-3529-1407
-
tuw.author.orcid
0000-0001-7001-4481
-
tuw.event.name
SEC '25: 34th USENIX Conference on Security Symposium
en
tuw.event.startdate
13-08-2025
-
tuw.event.enddate
15-08-2025
-
tuw.event.online
On Site
-
tuw.event.type
Event for scientific audience
-
tuw.event.place
Seattle
-
tuw.event.country
US
-
tuw.event.presenter
Beer, Philipp
-
wb.sciencebranch
Informatik
-
wb.sciencebranch
Mathematik
-
wb.sciencebranch.oefos
1020
-
wb.sciencebranch.oefos
1010
-
wb.sciencebranch.value
80
-
wb.sciencebranch.value
20
-
item.openairecristype
http://purl.org/coar/resource_type/c_5794
-
item.fulltext
no Fulltext
-
item.cerifentitytype
Publications
-
item.grantfulltext
none
-
item.openairetype
conference paper
-
item.languageiso639-1
en
-
crisitem.author.dept
E192-06 - Forschungsbereich Security and Privacy
-
crisitem.author.dept
E192-06 - Forschungsbereich Security and Privacy
-
crisitem.author.dept
E192-06 - Forschungsbereich Security and Privacy
-
crisitem.author.dept
E192-06 - Forschungsbereich Security and Privacy
-
crisitem.author.orcid
0009-0009-6923-0027
-
crisitem.author.orcid
0000-0002-3105-0903
-
crisitem.author.orcid
0009-0004-3529-1407
-
crisitem.author.orcid
0000-0001-7001-4481
-
crisitem.author.parentorg
E192 - Institut für Logic and Computation
-
crisitem.author.parentorg
E192 - Institut für Logic and Computation
-
crisitem.author.parentorg
E192 - Institut für Logic and Computation
-
crisitem.author.parentorg
E192 - Institut für Logic and Computation
-
crisitem.project.funder
WWTF Wiener Wissenschafts-, Forschu und Technologiefonds