Demos

1. Activity hijacking attack steals your password and SSN in H&R Block appIn this video we show an unprivileged app running in the background can track H&R Block app's running state (we call such state UI state), unnoticeably hijack the foreground Activity and steal user's H&R block login credentials and social security number(SSN).

2. Camera peeking attack steals your personal check image in Chase app: In this video we show an unprivileged app running in the background can track Chase app's running state (we call such state UI state), and steal the check photo shot by the user. From the check photo, the attacker can successfully get many highly-sensitive personal information such as home address, check recipient name, bank routing number, account number, and even the user’s signature.

3. Activity hijacking attack steals your credit card number and shopping ship address information in NewEgg appIn this video we show an unprivileged app running in the background can track NewEgg app's running state (we call such state UI state), unnoticeably inject two Activities into foreground and steal user's credit card number and shopping ship address information.