Pre-installed apps; Sensitive data; Android; Static analysis; Low-cost devices; Africa
Abstract :
[en] Pre-installed system and vendor applications on low-cost Android devices can run with elevated privileges yet receive little independent scrutiny. In this work, we present PiPLAnD, a pipeline that extracts APKs from physical devices and applies static analysis to detect sensitive-data leaks, manifest misconfigurations, and suspicious behaviors in pre-installed apps. Using PiPLAnD, we analyzed 1544 pre-installed APKs collected from seven devices (Infinix, itel, Tecno). Our findings show that 145 apps (9%) leak sensitive information, 249 apps (16%) export sensitive components without adequate protection, and numerous apps exhibit risky behaviors (226 execute dangerous commands, 79 access/send/delete SMS, 33 perform silent installation actions). We also identified a vendor-shipped package that appears to exfiltrate device identifiers and location to a third-party vendor. These results indicate that pre-installed software on widely distributed, low-cost devices can pose real privacy and security risks to end users.
Disciplines :
Computer science
Author, co-author :
DIALLO, Alioune ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
KABORE, Abdoul Kader ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SNT Office > Project Coordination
PILGUN, Aleksandr ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
SAMHI, Jordan ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
BISSYANDE, Tegawendé ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
KLEIN, Jacques ; University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
External co-authors :
yes
Language :
English
Title :
On the security of pre-installed Android apps in low-cost devices
Publication date :
In press
Number of pages :
18
Event name :
17th EAI International Conference on Africa Internet infrastructure and Services (EAI AFRICOMM)
Event place :
Ile-Ife, Nigeria
Event date :
from 23 to 26 November 2025
Audience :
International
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Name of the research project :
R-AGR-3790 - LuxWays - part UL - BISSYANDE Tegawendé