Unpublished conference/Abstract (Scientific congresses, symposiums and conference proceedings)
On the security of pre-installed Android apps in low-cost devices
DIALLO, Alioune; DIOP, Anta; KABORE, Abdoul Kader et al.
In press17th EAI International Conference on Africa Internet infrastructure and Services (EAI AFRICOMM)
Peer reviewed
 

Files


Full Text
Preinstalled_apps.pdf
Author postprint (1.32 MB)
Request a copy

All documents in ORBilu are protected by a user license.

Send to



Details



Keywords :
Pre-installed apps; Sensitive data; Android; Static analysis; Low-cost devices; Africa
Abstract :
[en] Pre-installed system and vendor applications on low-cost Android devices can run with elevated privileges yet receive little independent scrutiny. In this work, we present PiPLAnD, a pipeline that extracts APKs from physical devices and applies static analysis to detect sensitive-data leaks, manifest misconfigurations, and suspicious behaviors in pre-installed apps. Using PiPLAnD, we analyzed 1544 pre-installed APKs collected from seven devices (Infinix, itel, Tecno). Our findings show that 145 apps (9%) leak sensitive information, 249 apps (16%) export sensitive components without adequate protection, and numerous apps exhibit risky behaviors (226 execute dangerous commands, 79 access/send/delete SMS, 33 perform silent installation actions). We also identified a vendor-shipped package that appears to exfiltrate device identifiers and location to a third-party vendor. These results indicate that pre-installed software on widely distributed, low-cost devices can pose real privacy and security risks to end users.
Disciplines :
Computer science
Author, co-author :
DIALLO, Alioune  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
DIOP, Anta;  Ecole Supérieure Polytechnique de Dakar - Sénégal > Génie Informatique
KABORE, Abdoul Kader  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > SNT Office > Project Coordination
PILGUN, Aleksandr  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
SAMHI, Jordan  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
BISSYANDE, Tegawendé  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
KLEIN, Jacques  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
External co-authors :
yes
Language :
English
Title :
On the security of pre-installed Android apps in low-cost devices
Publication date :
In press
Number of pages :
18
Event name :
17th EAI International Conference on Africa Internet infrastructure and Services (EAI AFRICOMM)
Event place :
Ile-Ife, Nigeria
Event date :
from 23 to 26 November 2025
Audience :
International
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Name of the research project :
R-AGR-3790 - LuxWays - part UL - BISSYANDE Tegawendé
Commentary :
To appear
Available on ORBilu :
since 17 December 2025

Statistics


Number of views
85 (8 by Unilu)
Number of downloads
0 (0 by Unilu)

Bibliography


Similar publications



Contact ORBilu