Skip to finding
§
High
Mobile — Android
Confirmed

A no-permission Android app can help an off-path sender hijack other apps’ TCP connections and poison shared DNS.

Cross-app side channels supply transport state that Android’s permission boundary was expected to keep unavailable.

Affects

Android, the mobile operating system used on phones and tablets.

What it enables

Cross-app TCP connection hijacking and DNS cache poisoning

The victim runs an ordinary attacker-controlled Android app requiring no permissions.→↓The app uses cBPF truncation or IP-options behavior and bind-based port probing to infer another app’s connection or the resolver’s query state.→↓The app communicates the inferred state to an off-path node able to transmit spoofed-source packets.→↓The node races forged TCP SYN/ACK or DNS responses against the legitimate endpoint.→↓A new unauthenticated TCP connection is diverted or Android’s shared resolver caches an attacker-selected address.
Why this matters

This leads because an ordinary app with no permissions can contribute to altering another app’s traffic or Android’s shared DNS state when paired with a spoof-capable sender.

Detail and 2 sources
Required access

Execution as an ordinary no-permission app on the victim plus an off-path internet node able to transmit spoofed-source packets through a port-preserving network; the targeted traffic must lack effective end-to-end authentication

Affected versions

Android 16 with Linux kernel 6.1.145, demonstrated on a Google Pixel 9

Proof of concept

Demonstrated by the researcher

The app measures cBPF, IP-options, and port-allocation behavior, relays the inferred state to an off-path node, and lets that node race forged TCP or DNS packets against the legitimate endpoint.

On a Pixel 9, the researchers reported 80–86% success for TCP hijacking and 100% for DNS poisoning under their stated trial conditions.

Those trials do not establish the same results across every Android release, kernel, and router configuration.

Evidence
The primary paper reports end-to-end Pixel 9 experiments, including 80–86% TCP-hijack success and 100% DNS-poisoning success in its stated trials.The demonstrated result generalizes to every Android release, kernel and router configuration.Public artifact code reproduces the Android attacks.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 12, 2026