Abstract
In this paper, we present a novel family of USB-based attacks on mobile devices, ChoiceJacking, which is the first to bypass existing Juice Jacking mitigations. We observe that these mitigations assume that an attacker cannot inject input events while establishing a data connection. However, we show that this assumption does not hold in practice. We present a platform-agnostic attack principle and three concrete attack techniques for Android and iOS that allow a malicious charger to autonomously spoof user input to enable its own data connection. Our evaluation using a custom cheap malicious charger design reveals an alarming state of USB security on mobile platforms. Despite vendor customizations in USB stacks, ChoiceJacking attacks gain access to sensitive user files (pictures, documents, app data) on all tested devices from 8 vendors including the top 6 by market share. For two vendors, our attacks allow file extraction from locked devices. For stealthily performing attacks that require an unlocked device, we use a power line side-channel to detect suitable moments, i.e., when the user does not notice visual artifacts.
We responsibly disclosed all findings to affected vendors. All but one (including Google, Samsung, Xiaomi, and Apple) acknowledged our attacks and are in the process of integrating mitigations.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the 34th USENIX Security Symposium |
| Pages | 4363-4379 |
| Number of pages | 17 |
| ISBN (Electronic) | 9781939133526 |
| Publication status | Published - 2025 |
| Event | 34th USENIX Security Symposium: USENIX Security 2025 - Seattle, United States Duration: 13 Aug 2025 → 15 Aug 2025 Conference number: 34 https://www.usenix.org/conference/usenixsecurity25 |
Publication series
| Name | Proceedings of the 34th USENIX Security Symposium |
|---|
Conference
| Conference | 34th USENIX Security Symposium |
|---|---|
| Abbreviated title | USENIX'25 |
| Country/Territory | United States |
| City | Seattle |
| Period | 13/08/25 → 15/08/25 |
| Internet address |
Keywords
- Mobile Security
ASJC Scopus subject areas
- Safety, Risk, Reliability and Quality
- Computer Networks and Communications
- Information Systems
Fields of Expertise
- Information, Communication & Computing
Fingerprint
Dive into the research topics of 'ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade ago'. Together they form a unique fingerprint.Projects
- 2 Finished
-
SEIZE - Secure Edge Devices For Industrial Zero-Trust Environments
Mangard, S. (Consortium manager resp. coordinator with external organisations) & Mangard, S. (Project manager on research unit)
1/01/22 → 31/12/24
Project: Research project
-
A-SIT - Secure Information Technology Center Austria
Posch, R. (Project manager), Oswald, M. E. (Other function), Payer, U. (Other function), Neuherz, E. (Other function), Ivkovic, M. (Attendee), Tauber, A. (Attendee), Reiter, A. (Attendee), Zefferer, T. (Attendee), Kreuzhuber, S. (Attendee), Rössler, T. (Other function), Mangard, S. (Attendee), Bratko, H. (Other function), Dietrich, K. (Attendee), Stranacher, K. (Attendee), Bonato, M. (Other function), Bauer, W. (Attendee), Orthacker, C. (Attendee), Wolkerstorfer, J. (Attendee), Zwattendorfer, B. (Attendee), Aigner, M. J. (Other function), Scheibelhofer, K. (Other function), Suzic, B. (Attendee), Knall, T. (Other function), Leitold, H. (Coordinator), Bratko, D. (Attendee), Dominikus, S. (Attendee), Lipp, P. (Attendee), Marsalek, A. (Attendee), Reimair, F. (Attendee), Feichtner, J. (Attendee) & Teufl, P. (Attendee)
21/05/99 → 31/12/24
Project: Research area
Activities
- 2 Talk at conference or symposium
-
ChoiceJacking via Malicious Chargers
Draschbacher, F. (Speaker)
26 Jun 2025Activity: Talk or presentation › Talk at conference or symposium › Science to public
-
ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade ago
Draschbacher, F. (Speaker)
14 Aug 2025Activity: Talk or presentation › Talk at conference or symposium › Science to science
Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS