New Android TapTrap attack fools users with invisible UI trick

Discussion in 'mobile device security' started by reasonablePrivacy, Jul 11, 2025.

  1. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,276
    Location:
    Member state of European Union
    https://www.bleepingcomputer.com/news/security/new-android-taptrap-attack-fools-users-with-invisible-ui-trick/

    Mitigation is mentioned (inside accessibility settings)
     
  2. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,558
    Location:
    U.S.A. (South)
    The device wiping angle is particularly vicious.
     
  3. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,533
    How is Google Android not going to "fix/plug" this leak with an almost instant update release?

    Funny I just tried to paste the link above but my TOR node is blocked. So finding the cure is secure, LOL
     
  4. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,959
    Location:
    Outer space
    They have been aware of this for a long time now:

    https://taptrap.click/

    And it's part of functionality, though with all the media attention Google might change their opinion:
    https://grapheneos.social/@GrapheneOS/114895041566978956
     
  5. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,276
    Location:
    Member state of European Union
    Given a chance I would 10 out of 10 times took wiping of my phone than giving access to my banking app.

    Media and companies producing apps. I asked my two banks yesterday whether their apps are mitigating that vulnerability or should I disable animations. I'm waiting for answer. If enough consumer will ask high-profile app developers about that, then Google will have to address that.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.