Android Permissions: Evolution, Attacks, and Best Practices

IEEE Security & Privacy (2024)

Abstract

In this article, we study the evolution of Android permissions. We describe the rationale behind key changes in Android’s permission model and disclose two permission-related security vulnerabilities we discovered. Finally, we provide developers actionable insights to proactively address permission-related security and privacy risks during development.