A new type of tapjacking attack, dubbed TapTrap, can exploit UI (User Interface) animations to bypass Android's permission system and allow access to sensitive data or trick users into performing destructive actions, such as erasing all data on the device.
See also: Android spyware Catwatchful leaks 62,000 user logins

Unlike traditional tapjacking attacks that rely on overlapping elements, TapTrap attacks work even through apps without any permissions, launching a harmless, transparent activity on top of a malicious one. This behavior remains unchecked in Android versions 15 and 16.
The TapTrap technique was developed by a team of security researchers from TU Wien and the University of Bayreuth (Philipp Beer, Marco Squarcina, Sebastian Roth, Martina Lindorfer) and is set to be presented next month at the USENIX Security Symposium. However, the team has already published a technical paper describing the attack, as well as a website summarizing the key points.
The TapTrap attack exploits the way Android handles activity transitions with custom animations, creating a visual discrepancy between what the user sees and what the device actually records.
See also: SparkKitty attacks iOS and Android devices through their App Stores
A malicious application installed on the target device launches a sensitive system screen (such as a permission request, system setting, etc.) through another application, using the startActivity() with a custom, low-transparency animation. Although the application window receives all user touches, the user only sees the underlying application, which displays its own interface — while actually interacting with the nearly invisible screen above it.

Thinking they are interacting with the harmless application, the user may tap on areas of the screen that correspond to dangerous actions, such as “Allow” or “Authorize” buttons in nearly invisible windows.
A video published by researchers shows how a seemingly innocent gaming app can leverage the TapTrap attack to enable camera access for a website through the Chrome.
To see if TapTrap could work with apps available on the Play Store, Android's official repository, the researchers analyzed nearly 100,000 apps. They found that 76% of them are vulnerable to the TapTrap attack.
See also: Android malware Godfather uses virtualization techniques
Based on the above, it is clear that the TapTrap attack highlights a critical security gap in the Android interface management system, which so far remains inadequately addressed. The fact that the vast majority of applications in the Play Store (76%) are vulnerable shows that this is not a theoretical or rare scenario, but a widely applicable attack that can be exploited in practice.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
