Attention! Your Copied Data is Under Monitoring: A Systematic Study of Clipboard Usage in Android Apps

Yongliang Cheng, Ruoqin Tang, Chaoshun Zuo, Xiaokuan Zhang, Xue Lei, Xiapu Luo, Qingchuan Zhao

Research output: Chapter in book / Conference proceedingConference article published in proceeding or bookAcademic researchpeer-review

Abstract

Recently, clipboard usage has become prevalent in mobile apps allowing users to copy and paste text within the same app or across different apps. However, insufficient access control on the clipboard in the mobile operating systems exposes its contained data to high risks where one app can read the data copied in other apps and store it locally or even send it to remote servers. Unfortunately, the literature only has ad-hoc studies in this respect and lacks a comprehensive and systematic study of the entire mobile app ecosystem. To establish the missing links, this paper proposes an automated tool, ClipboardScope, that leverages the principled static program analysis to uncover the clipboard data usage in mobile apps at scale by defining a usage as a combination of two aspects, i.e., how the clipboard data is validated and where does it go. It defines four primary categories of clipboard data operation, namely spot-on, grand-slam, selective, and cherry-pick, based on the clipboard usage in an app. ClipboardScope is evaluated on 26,201 out of a total of 2.2 million mobile apps available on Google Play as of June 2022 that access and process the clipboard text. It identifies 23,948, 848, 1,075, and 330 apps that are recognized as the four designated categories, respectively. In addition, we uncovered a prevalent programming habit of using the SharedPreferences object to store historical data, which can become an unnoticeable privacy leakage channel.
Original languageEnglish
Title of host publicationProceedings of the IEEE/ACM 46th International Conference on Software Engineering
Pages1–13
Publication statusPublished - Apr 2024

Fingerprint

Dive into the research topics of 'Attention! Your Copied Data is Under Monitoring: A Systematic Study of Clipboard Usage in Android Apps'. Together they form a unique fingerprint.

Cite this