Android devices are leaking contact tracing data all over the place

Contact tracing app
(Image credit: Future)

If you have a contact tracing app installed on your Android smartphone, it could be leaking data to other apps according to new research from the privacy and security firm AppCensus.

Last year Google and Apple teamed up to develop a contact tracing API which uses Bluetooth and GPS data to provide a low-cost solution to find out who those infected with Covid-19 came in contact with. Contact tracing has traditionally been done manually but due to the prevalence of smartphones today, tech giants and governments around the world decided to work together to use technology to stop the virus' spread.

While Google and Apple developed their Exposure Notifications System (ENS) to power contact tracing apps, hundreds of third-party apps on Android were given access to the sensitive data collected from users' devices. This is because Google decided to store all of the sensitive data collected by ENS in the system logs of Android smartphones.

Although not all apps are able to read system logs on Android, the search giant does allow some hardware manufacturers, telecoms and commercial partners to pre-install “privileged” apps which are able to access system logs.

Leaking contact tracing data

In a new blog post, co-founder and forensics lead of AppCensus, Joel Reardon points out the fact that Xiaomi's Redmi Note 9 allows 54 apps to read system logs while the Samsung Galaxy A11 does so with 89 apps. As a result, many apps that don't need to access a device's contact tracing data had it shared with them on Android.

In order for smartphones to be used for contact tracing, apps using Android and Google's API emit anonymous identifiers that change periodically called rolling proximity identifiers (RPIs) that are broadcast over Bluetooth. These RPIs are then used to determine who a person may have come in contact with while they were infected with Covid-19.

According to AppCensus, RPIs that are broadcast and those that are heard by other devices can be found in the system logs of Android devices. Devices that hear another smartphone's RPIs also log the current Bluetooth MAC address of the sending device. While RPIs and Bluetooth Mac addresses are random and anonymized, AppCensus was able to identify several ways that this data can be used to carry out privacy attacks.

After making this discovery, the firm quickly reached out to Google though the search giant did not acknowledge or fix the issue at the time. AppCensus then made its findings public after 60 days had elapsed which is a bit shorter than Project Zero's own 90-day disclosure period.

In a statement to ZDNet, a Google spokesperson explained that the company had already looked into the issue and that an update first began rolling out to Android devices several weeks ago to fix it, saying:

"We were notified of an issue where the Bluetooth identifiers were temporarily accessible to some pre-installed applications for debugging purposes. Immediately upon being made aware of this research, we began the necessary process to review the issue, consider mitigations and ultimately update the code. These Bluetooth identifiers do not reveal a user's location or provide any other identifying information and we have no indication that they were used in any way – nor that any app was even aware of this." 

Via ZDNet

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Stalkerware
New spyware found to be snooping on thousands of Android and iOS users
Kaspersky Report on Stalkerware
Security flaw in popular stalkerware apps is exposing phone data of millions
Map shown on smartphone
Thousands of GPS tracking customers have info leaked following data breach
Photograph of a hand holding a smartphone with two googly eyes
Every tap, every message – how to stop your smartphone spying on you
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Which apps were most hungry for your data in 2024?
Data breach
Privacy of millions worldwide compromised as huge data location broker got hacked
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection