The Danger of Minimum Exposures

Understanding Cross-App Information Leaks on iOS through Multi-Side-Channel Learning

Video Demo


Traces

The following figures show the traces of global statistics when three iOS apps, YouTube, Amazon, and Spotify are launched. Each data point in the figures shows the value change of the channel compared to the last reading. The APIs are called periodically at the frequency of 500 times per second. We can see from the figure that the user’s activities can be roughly identified by eyeballing the traces of CPU, memory, and network statistics.

en0 ipackets

en0 opackets

en0 ibytes

en0 obytes

cow faults

wire count

user time

Responsible Disclosure