A no-permission Android app can help an off-path sender hijack other apps’ TCP connections and poison shared DNS.
Cross-app side channels supply transport state that Android’s permission boundary was expected to keep unavailable.
Affects
Android, the mobile operating system used on phones and tablets.
What it enables
Cross-app TCP connection hijacking and DNS cache poisoning
The victim runs an ordinary attacker-controlled Android app requiring no permissions.→↓The app uses cBPF truncation or IP-options behavior and bind-based port probing to infer another app’s connection or the resolver’s query state.→↓The app communicates the inferred state to an off-path node able to transmit spoofed-source packets.→↓The node races forged TCP SYN/ACK or DNS responses against the legitimate endpoint.→↓A new unauthenticated TCP connection is diverted or Android’s shared resolver caches an attacker-selected address.
Why this matters
This leads because an ordinary app with no permissions can contribute to altering another app’s traffic or Android’s shared DNS state when paired with a spoof-capable sender.
Detail and 2 sources
Required access
Execution as an ordinary no-permission app on the victim plus an off-path internet node able to transmit spoofed-source packets through a port-preserving network; the targeted traffic must lack effective end-to-end authentication
Affected versions
Android 16 with Linux kernel 6.1.145, demonstrated on a Google Pixel 9
Proof of concept
Demonstrated by the researcher
The app measures cBPF, IP-options, and port-allocation behavior, relays the inferred state to an off-path node, and lets that node race forged TCP or DNS packets against the legitimate endpoint.
On a Pixel 9, the researchers reported 80–86% success for TCP hijacking and 100% for DNS poisoning under their stated trial conditions.
Those trials do not establish the same results across every Android release, kernel, and router configuration.
Evidence
The primary paper reports end-to-end Pixel 9 experiments, including 80–86% TCP-hijack success and 100% DNS-poisoning success in its stated trials.The demonstrated result generalizes to every Android release, kernel and router configuration.Public artifact code reproduces the Android attacks.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.