A vulnerability in Google’s Android mobile operating system allows attackers to confirm you are their desired target before unleashing malicious code that they know would only work for a short time, new research authored by a New Jersey Institute of Technology student found.

Robert Blacha was lead author of Leaky Apps: Targeted Deanonymization on Mobile Phones which won Best Paper at the ACM Conference on Data and Application Security and Privacy, in Frankfurt, Germany this summer. The work took place before Blacha graduated in May from Ying Wu College of Computing with an M.S. in cybersecurity and privacy program.

Blacha is from Wayne, N.J. and transferred to NJIT as a sophomore after attending the U.S. Military Academy at West Point. He left the academy for medical reasons and chose NJIT because he liked the research focus here, having already been part of a cybersecurity security group in the Army institution. He cold-emailed computer science Prof. Reza Curtmola upon arriving in Newark and the pair began collaborating, along with Associate Prof. Yossi Oren from Israel’s Ben-Gurion University of the Negev. Their goal was to see if vulnerabilities already known by Curtmola and Oren on desktop computers also applied to mobile phones.

They found that the problem was not merely present but was actually worse on mobile phones. That’s because mobile operating systems have multiple digital doors that attackers could enter — a larger attack surface, in technical jargon — compared to only one point on ordinary computers. For example, a desktop or laptop computer might have one or two browsers, such as Edge or Safari, and perhaps Chrome. But an Android phone has Chrome; perhaps Firefox; Samsung’s own browser; and a Meta in-app browser for Facebook and Instagram. Turning off third-party cookies helps, but the more ways in, the more vulnerable, just like a house or office, Blacha explained.

The attack works by emailing a file or link to the intended recipient and tricking them into opening it, such as through a deceitful message or website. The file or link contains a video which could be as small as one pixel and without audio, so the recipient may not even know it’s playing. Applications such as Youtube can’t be uninstalled on Android phones, nor can video links be stopped from automatically opening the contents they support.

An attacker’s software would detect that opening the video led to the mobile device’s memory usage abruptly increasing, in turn confirming that the correct person received it — and then the attacker could deploy their real mission, knowing it won’t be wasted on the wrong person.

The real mission is likely to occur through what’s called a zero-day attack, meaning it’s an undocumented security loophole for which a solution is not yet available. Such attacks rarely stay secret for long, so malicious actors tend to save these for their most important and hardest-to-reach targets.

“Because I can form a crafted link for your YouTube account, and because different browsers that purport to be secure, like Tor, don't properly handle this link, I can execute the attack on you. If I know your Google account, like your Gmail, I can determine if you are accessing my website or not,” Blacha said.

“We had hundred-page Google docs of me just taking notes and [Curtmola] advising me on where to expand it next. The Best Paper award is probably more thanks to him than it is to me … I'm not a good writer. He very much helped me clean it up and package it in a way that is much more palatable,” Blacha added. “It's nice to know that all of the work we put into it isn't all for naught. It's definitely going on my resume. It's definitely going on my LinkedIn. It's a nice accolade to have before going into the real workforce.”

For Blacha, his first career stop will be MIT’s Lincoln Lab as an embedded systems engineer. The federally-funded laboratory in Lexington, Mass. has a track record of historic research developments in computing. Blacha said he’ll work on two existing research projects there. The first is expanding the feature set of an operating system kernel called SEL4 which is highly secure due to formal mathematical verification. The second is an effort to prove semantic equivalency between code translated from C into Rust. There is a government-wide movement to switch from legacy C programming code into modern Rust, which is known for preventing memory leaks but is harder to learn. “One of the things that they're looking at is odd behaviors by the C compiler that might not translate into Rust,” such as the command called sizeof which tells developers how much memory is used, Blacha said.

Meanwhile, the research at NJIT continues. Curtmola, Oren and future students will look to study defenses against the kind of attacks that Blacha revealed. “The browser vendors have acknowledged that these are strong attacks that are difficult to prevent,” Curtmola said. “In addition to technical solutions, developing practical defenses is a multi-pronged effort that requires working with various stakeholders, such as browser vendors and standardization bodies, as well as considering usability and human factors.”

“I enjoyed working with Robert, both as part of the CyberCorps SFS program at NJIT, and as part of this research project,” Curtmola added. “He's got a lot of raw talent which I tried my best to polish and mentor. I think he's got a bright future, he's passionate about what he's doing and he can accomplish anything he puts his mind to.”

Blacha said he advises current undergraduates to get into research, go to job fairs and do their own technical projects. “People frequently get a little too concerned with GPA,” he said. “One of the things that Lincoln Labs liked about me was that I wrote in a library in C that handles integers of arbitrary size, which shows a lot more about the knowledge of how to code in C than taking CS-288 and getting an A.”