
Yossi Oren
Leaky Apps
Targeted Deanonymization on Mobile Phones
Targeted Deanonymization attacks allow an attacker who controls a website to infer the identity of specific target users browsing that website. They are a severe privacy risk, as they can then be used to carry out highly-Targeted attacks against the inferred identities. These attacks were previously shown to be practical in the desktop environment. In this work, we set to investigate the feasibility of targeted deanonymization in a mobile setting, which presents new opportunities but also new challenges for the attacker. We discover a surprising reality: The attack surface for targeted deanonymization on mobiles is larger than in the desktop setting. We replicate successfully on the Android system all the scenarios that were possible in the desktop setting, and also introduce new attack variants specific to the mobile setting. Notably, the app pop-up variant leverages Android intents to bypass the need for web cookies altogether. We present a decision tree that the attacker can navigate to select the appropriate attack variant, depending on the specific configuration on target user's mobile device. We show that the attacker can target an overwhelming majority of mobile users, including multiple mobile browsers, in-App browsers embedded into common apps, and many resource-sharing services, with attack accuracies and times comparable to those in the desktop setting. We also discuss defenses specific to the mobile setting, ranging from those that can be enabled by users to those that can be deployed by app developers, resource-sharing services, and mobile OS and browser vendors.
| Publication language | English |
| Pages | 205-217 |
| Publication status | Published - 22.06.2026 |