Security Evaluation of Android apps in budget African Mobile Devices
By: Alioune Diallo , Anta Diop , Abdoul Kader Kabore and more
Potential Business Impact:
Finds hidden dangers in cheap phones.
Android's open-source nature facilitates widespread smartphone accessibility, particularly in price-sensitive markets. System and vendor applications that come pre-installed on budget Android devices frequently operate with elevated privileges, yet they receive limited independent examination. To address this gap, we developed a framework that extracts APKs from physical devices and applies static analysis to identify privacy and security issues in embedded software. Our study examined 1,544 APKs collected from seven African smartphones. The analysis revealed that 145 applications (9%) disclose sensitive data, 249 (16%) expose critical components without sufficient safeguards, and many present additional risks: 226 execute privileged or dangerous commands, 79 interact with SMS messages (read, send, or delete), and 33 perform silent installation operations. We also uncovered a vendor-supplied package that appears to transmit device identifiers and location details to an external third party. These results demonstrate that pre-installed applications on widely distributed low-cost devices represent a significant and underexplored threat to user security and privacy.
Similar Papers
How Do Mobile Applications Enhance Security? An Exploratory Analysis of Use Cases and Provided Information
Cryptography and Security
Finds best apps to keep phones safe.
Security and Privacy Assessment of U.S. and Non-U.S. Android E-Commerce Applications
Cryptography and Security
Finds security flaws in shopping apps.
"Your Doctor is Spying on You": An Analysis of Data Practices in Mobile Healthcare Applications
Cryptography and Security
Finds health apps secretly spying on you.