“Surreptitious Sharing Attacks”: A new type of attack targets Android Apps and leads to the leakage of personal data.

At the GI Sicherheit 2016 conference held in Bonn, Germany, two security researchers revealed a new type of attack targeting Android devices called “Surreptitious Sharing.”.
The problem is buried deep in the Android API. The two researchers, Dominik Schürmann and Lars Wolf, explain that the issue affects links shared through apps, for which Android uses Uniform Resource Identifiers (URIs) that refer to the actual location of the data on the device.
The researchers explain that the normal behavior would be for applications to send files as serialized content via the Intent API, and not use file scheme URIs.
They also state that the easiest way to mitigate this issue is to disallow specific MIME types when transferring or exchanging data within applications, and more specifically, they suggest disabling URI file schemes.
The concept is a bit difficult to grasp without deep knowledge of Android, which is why the two researchers provided two demos demonstrating the attack's capabilities.
#Example 1: Attackers can steal IMAP passwords
The researchers created a malicious app that, once installed on users' devices, displays a fake page informing victims that the app has crashed, as well as a button to send a supposed bug report to the app's creator.
The fake report error button contains a file scheme URI, which points to the exact location on the users' hard drive where the client's IMAP passwords are stored.
When users click on the link, an email application opens, and IMAP passwords are sent directly to the attackers. Users are not able to know what exactly has happened and think they have simply clicked on a link.
The researchers tested a total of four email apps, all of which were found to be vulnerable. The apps were Gmail, K-9 Mail, AOSP Mail, and WEB.DE.
#Example 2: Attackers can intercept private conversations from IM apps
In their second attack, the researchers created another malicious app, which encourages users to share an audio file via an IM app.
As before, the share link for the audio file has been crafted to point to the database file where conversations from users' messenger apps are stored. By clicking to share the audio file, users are actually sending the Messenger database to the attackers.
The researchers tested IM apps such as Skype, Hangouts, WhatsApp, Threema, Signal, Telegram, Snapchat, and Facebook Messenger. Threema, Signal, Telegram, and Skype were found to be vulnerable.
