Watch Your Phone: Novel USB-Based File Access Attacks Against Mobile Devices
Black Hat Asia 2025 · Day 2 · Briefings
Overview
In an era where mobile devices are indispensable repositories of sensitive personal data—from photographs and messages to login credentials—the security of these devices is paramount. This presentation by Floren Rasha and Lucas Ma unveils a series of novel USB-based attacks that challenge long-held assumptions about mobile device security on both iOS and Android platforms. The researchers demonstrate how attackers can bypass critical user confirmation prompts and even access data on locked devices, leveraging the ubiquitous USB interface.

Key moments
- 0:00 Introduction to novel USB-based file access attacks
- 1:10 Overview of two primary attack scenarios
- 2:10 Previous USB attacks and user confirmation prompt mitigation
- 4:00 USB Type-C dual role and power delivery capabilities
- 4:50 Detailed explanation of user confirmation prompt
- 6:00 Introducing the malicious phone charger attack scenario
- 6:50 Identified conceptual flaw in user confirmation prompt mitigation
- 8:00 Malicious charger attack using Bluetooth and PD swaps
Watch Your Phone: Novel USB-Based File Access Attacks Against Mobile Devices
Speakers: Floren Rasha, PhD Student, GR University of Technology; Lucas Ma, PhD Candidate, K University of Technology
Conference: Black Hat Asia
YouTube: https://www.youtube.com/watch?v=UYKet66vLsg
Overview
In an era where mobile devices are indispensable repositories of sensitive personal data—from photographs and messages to login credentials—the security of these devices is paramount. This presentation by Floren Rasha and Lucas Ma unveils a series of novel USB-based attacks that challenge long-held assumptions about mobile device security on both iOS and Android platforms. The researchers demonstrate how attackers can bypass critical user confirmation prompts and even access data on locked devices, leveraging the ubiquitous USB interface.
The talk dissects two primary attack scenarios. The first involves a malicious phone charger that surreptitiously extracts data, circumventing the user consent mechanisms designed to prevent such "juice jacking" attacks. The second scenario focuses on an attacker with physical access to a locked device, proving that data thought to be protected by the lock screen or encryption can still be compromised. These findings highlight significant conceptual flaws and implementation vulnerabilities, urging a re-evaluation of current mobile security models and user practices.
Background
▶ Watch: Introduction to novel USB-based file access attacks (0:00)
Mobile devices have become central to daily life, accumulating vast amounts of sensitive user data, naturally making them attractive targets for malicious actors. The USB interface stands out as a primary entry point for such attacks, a vector that has been exploited for over two decades. Historically, USB-based attacks on mobile devices have fallen into two main categories: those operating as malicious USB devices (like chargers) and those exploiting physical access to locked devices.
Early attacks, notably the infamous "juice jacking" incidents, involved malicious chargers acting as USB hosts to extract data via protocols like the Media Transfer Protocol (MTP). Both iOS and Android swiftly mitigated these by introducing user confirmation prompts. When a device is connected to a USB host, data access is only granted after the user explicitly unlocks the device and confirms the prompt, a measure widely considered effective. However, subsequent attacks pivoted to operating as USB peripherals, where no such prompts were implemented, though their capabilities remained limited (e.g., mirroring screen content via USB to HDMI).
On the other hand, attacks requiring physical access to a locked device typically exploit low-level implementation flaws, often targeting specific devices or manufacturers. Examples include the Checkm8 bootrom vulnerability that compromised iOS devices and techniques used by commercial forensics tools like Cellebrite. All these attacks, regardless of their nature, leverage the USB port as their primary vector.
Modern mobile devices are universally equipped with USB Type-C connectors, which are highly versatile. These ports handle both data and power, with both being bidirectional. This means a device can charge itself or supply power to peripherals, and crucially, it can act as either a USB host (connecting keyboards, mice) or a USB peripheral (connecting to a computer as a flash drive). The negotiation of these power and data roles is managed by the USB Power Delivery protocol, which runs over dedicated data lines. A critical, often overlooked, aspect of USB-C is that while a port can assume either role, it can only function as one at any given time.
The user confirmation prompt, introduced as a defense against "juice jacking," functions as follows: when a mobile device is connected to a USB-C host (e.g., a computer), it initially appears as an MTP device but displays no files. The user must first unlock the device and then explicitly accept the on-screen prompt. Only after this confirmation does the mobile device expose its files over the MTP connection, ensuring intentional data access by the legitimate user. The researchers' work builds on identifying conceptual flaws in these very mitigations.
Key Findings
▶ Watch: Previous USB attacks and user confirmation prompt mitigation (2:10)
The researchers uncovered several critical vulnerabilities across both iOS and Android, demonstrating that existing USB security models have significant shortcomings. Their findings challenge the efficacy of user confirmation prompts and assumptions about data security on locked devices.
Malicious Phone Charger Scenario (Bypassing User Prompts)
- Cross-Platform "Choice Jacking" with Bluetooth and Data Role Swaps:
The first major finding demonstrated a sophisticated attack working on both iOS and Android. This attack leverages a combination of USB Power Delivery data role swaps and a hidden Bluetooth input device within the malicious charger. The charger first acts as a USB device, injects input events to enable Bluetooth scanning, pairs with the device via the hidden Bluetooth input device, and then uses input injection to accept the pairing request. Crucially, it then performs a data role swap to become a USB host. Once in host mode, it initiates an MTP handshake, triggering the user confirmation prompt, which is then accepted autonomously by the Bluetooth input device. This allows the charger to stealthily extract MTP files. Apple acknowledged this vulnerability, assigning a CVE and mitigating it in iOS 18.4. Google also acknowledged the attack and implemented mitigations in the Android Open Source Project (AOSP).
- Faster Android Attack via Open Accessory Protocol (AAP) Bypass:
For Android devices, a significantly faster attack was discovered by exploiting a flaw in Android's Open Accessory Protocol (AAP). AAP allows a USB host to send special USB control requests to inject input events. While the specification dictates this only works in a special accessory mode that doesn't allow concurrent MTP connections, the researchers found a bypass. A malicious charger can initiate an MTP connection (which triggers the user prompt) and then use AAP to inject input events to confirm that very prompt. This allows rapid and stealthy file access. Google was informed, and Android patching for this vulnerability is currently pending.
Physical Access to Locked Device Scenario (Bypassing Encryption Assumptions)
- Huawei Locked Device Data Truncation (MTP Customization Vulnerability):
This finding exposed a critical vulnerability in a specific vendor's (Huawei) customization of the Android MTP stack. While Android's MTP implementation typically requires the MTP database to be populated only after user consent, the researchers found that Huawei's MTPDatabase.get_object_file_path method (for file handles above 10 million) directly queried the MediaStore database. This bypasses the standard MTP storage manager, allowing file path resolution even when the device is locked and no user consent has been given. Furthermore, the do_truncate_object MTP message handler, responsible for truncating files, lacked the hasStorage() sanity check present in most other handlers. By combining these, an attacker could send MTP_BEGIN_EDIT_OBJECT, MTP_TRUNCATE_OBJECT (with size zero), and MTP_END_EDIT_OBJECT messages for a range of file handles, effectively erasing all user data by truncating files to zero length on a locked device. The affected vendors developed patches for this.
- Android USB Manager Timeout Attack (Locked Device Full MTP Access):
A more general Android vulnerability was discovered by exploiting the USB Manager state machine. The set_enabled_functions method within the USB Manager, which is called when USB functions change, registers a 3-second timeout handler. If the device is not re-enumerated by the USB host within this period, the timeout triggers, restoring the USB functions to a default state specified by mScreenUnlockFunctions. This mScreenUnlockFunctions field is user-configurable in developer settings (e.g., "File transfer" which corresponds to MTP).
The attack leverages the fact that sending a special USB control request to start accessory mode invokes set_enabled_functions with FUNCTION_ACCESSORY, and this logic is reachable on a locked device. By sending this request and then deliberately delaying re-enumeration, the malicious host forces the 3-second timeout. If mScreenUnlockFunctions is set to MTP, the device's USB functions revert to full MTP mode, granting the attacker a 7-second window of full MTP access to the device's contents. This process can be repeated to extract entire disk contents in chunks. Google assigned a CVE for this and rolled out a patch in the November 2024 Android security update.
In summary, the key findings demonstrate that "juice jacking" style attacks are far from obsolete, evolving into sophisticated "choice jacking" attacks that bypass user prompts. Furthermore, even state-of-the-art devices and operating system versions remain vulnerable to data extraction and destruction, even when physically locked, challenging fundamental assumptions about mobile security.
Technical Deep Dive
▶ Watch: Detailed explanation of user confirmation prompt (4:50)
The attacks presented leverage intricate details of USB communication, operating system internals, and vendor-specific customizations.
Malicious Charger Scenario: Bypassing User Consent
Bluetooth Input Device & Data Role Swaps (iOS & Android)
This attack targets the conceptual flaw where users routinely unlock their devices while charging, creating an opportunity for autonomous prompt acceptance. The core challenge is that the USB specification dictates a port cannot simultaneously act as a host and a device, preventing a malicious charger from triggering and accepting a prompt at the same time. The researchers circumvent this with a multi-stage approach:
- Initial Connection: A victim connects their mobile phone to the modified charger. The charger initially acts as a USB device.
- Bluetooth Activation: The malicious charger injects input events (e.g., via a HID-over-USB interface, which requires no user consent) to navigate the device's UI and initiate Bluetooth scanning. This makes the device's Bluetooth MAC address discoverable.
- Bluetooth Pairing: A hidden Bluetooth input device within the charger (e.g., a virtual keyboard) initiates a Bluetooth pairing request with the victim device. The charger then injects input events to accept this pairing prompt.
- USB Data Role Swap: This is a critical step. Using the USB Power Delivery (PD) protocol, the malicious charger performs a data role swap, transitioning from a USB device (peripheral) to a USB host. USB-C's bidirectional nature and the PD protocol enable this dynamic role change.
- MTP Handshake & Prompt Acceptance: Now acting as a USB host, the charger initiates an MTP handshake with the victim device. This action triggers the standard user confirmation prompt for MTP access. Since the Bluetooth input device is already paired and configured, it can inject input events to autonomously accept this prompt.
- Data Extraction: With MTP access granted, the charger stealthily retrieves files from the device.
This attack, while effective, is relatively slow due to the multi-step process involving Bluetooth pairing and role swaps. Apple assigned a CVE (details not specified in talk) and addressed it in iOS 18.4. Google acknowledged the issue and implemented mitigations in AOSP.
Android Open Accessory Protocol (AAP) Bypass
Recognizing the slowness of the Bluetooth-based attack, the researchers found a much faster method specifically for Android by exploiting a flaw in Android's Open Accessory Protocol (AAP).
- AAP Capability: AAP allows a USB host to send special USB control requests to Android devices, including the ability to inject input events.
- Bypassing Limitations: The AAP specification dictates that this input injection capability only works while the Android device's USB port is in a special accessory mode, which explicitly does not allow concurrent MTP connections. However, the researchers discovered a bypass to this limitation.
- Attack Flow:
- The victim connects their Android device to the malicious charger.
- The charger immediately initiates an MTP connection, which triggers the user confirmation prompt.
- Crucially, the malicious charger then simultaneously uses AAP to inject input events, confirming the very prompt it just triggered.
- This grants immediate MTP access for file extraction.
The demonstration of this attack showed the user consent dialogue "hardly visible" – a "short flickering" – before it was autonomously confirmed, highlighting its speed and stealth. This vulnerability was disclosed to Google, and patching in Android is pending.
Physical Access Scenario: Bypassing Locked Device Protections
Huawei MTP Customization and Data Truncation
This attack specifically targeted vendor customizations in the Android MTP stack, demonstrating how deviations from the AOSP reference implementation can introduce critical vulnerabilities.
- Standard MTP on Android: In upstream AOSP, the MTP service interacts with the Linux kernel's function driver to receive MTP messages. The
MTP serverclass handles these messages, and theMTP databaseclass maintains a list of files for MTP. TheUSB Managerstarts the MTP service, but theMTP databaseremains empty until the user confirms the MTP consent prompt. This prompt callsUSB Manager.setCurrentFunctions()withFUNCTION_MTP, which restarts the MTP service, causing it to querycurrentFunctionsand, ifFUNCTION_MTPis enabled, populate the database viaMTPStorageManager.MTPStorageManagerthen enumerates files and assigns unique object handles (file handles). - Huawei Customization: The researchers found that one vendor (Huawei) modified the
MTPDatabaseclass, specifically theget_object_file_pathmethod, responsible for translating a file handle into an actual file path. For file handles above 10 million, this customized method performed a direct lookup in the MediaStore—a database of all user files on the device. - The Bypass: Critically, this MediaStore lookup did not depend on the
MTPStorageManagerbeing populated. This meant it functioned even when no storage volumes were added (i.e., user consent not given) and, most importantly, even while the device was locked. - Lack of Sanity Check: While most MTP message handlers (e.g.,
get_object_MTP_message_handler) included ahasStorage()sanity check to ensure storage volumes were added before processing requests, thedo_truncate_objectMTP message handler lacked this crucial check. - Attack Execution: With a locked Huawei device connected via USB:
- The attacker iterates through file handles starting from 10 million.
- For each handle, they send an
MTP_BEGIN_EDIT_OBJECTmessage. On the Android device, this opens a file descriptor corresponding to the path resolved by the vulnerableget_object_file_path. - Next, the attacker sends an
MTP_TRUNCATE_OBJECTmessage with a size of zero. This invokesftruncate(fd, 0)on the open file descriptor. - Finally, an
MTP_END_EDIT_OBJECTmessage closes the file descriptor. - Result: This effectively erases all user data by truncating the contents of all accessible files to zero length, leaving empty files with their original names.
This attack highlights the dangers of vendor customizations that deviate from security-hardened AOSP logic without proper scrutiny. The vulnerability was disclosed to affected vendors, who subsequently developed patches.
Android USB Manager Timeout Attack
This more general Android attack exploits a race condition within the USB Manager's state machine to gain full MTP access on a locked device.
- USB Manager Internals: The
USB Managermaintains amCurrentFunctionsfield, storing currently enabled USB functions (e.g., MTP, USB tethering). When this field changes,set_enabled_functionsis executed, which in turn callsset_USB_config. - Timeout Mechanism: A crucial part of
set_USB_configis the registration of a timeout handler that fires after a 3-second delay. If the device is re-enumerated by the USB host before these 3 seconds, the timeout is canceled. Otherwise, the timeout triggers, and the current USB functions are restored to a default state defined bymScreenUnlockFunctions. mScreenUnlockFunctions: This field represents the user's chosen default USB configuration in the developer settings (e.g., "File transfer," which corresponds to MTP). Many users might have this set to MTP for convenience. Crucially, the UI states that these settings "will be applied when another device is connected and your phone is unlocked," implying it's not active when locked.- Invoking
set_enabled_functionson a Locked Device: The researchers found that sending a special USB control request for starting accessory mode (part of AAP) invokesstart_accessory_modeinside theUSB Manager. This method, in turn, callsset_enabled_functionswithFUNCTION_ACCESSORY. This is key because this logic is reachable even on a locked device. - Triggering the Timeout: The malicious USB host connects to the locked device. It sends the USB control request to enable accessory mode. The Android device switches its USB descriptors and awaits re-enumeration by the host. However, the malicious host deliberately does not re-enumerate the device.
- MTP Access Window: After 3 seconds, the timeout handler triggers. Since
set_enabled_functionswas called (withFUNCTION_ACCESSORY), the timeout logic executes, restoring the USB functions tomScreenUnlockFunctions. IfmScreenUnlockFunctionsis set to MTP, the device's USB functions are now set to full MTP mode, granting the attacker access to the device's files. - Time Window: This MTP access is available for approximately 7 seconds before yet another timeout (not detailed in the talk but mentioned) kicks in, resetting the functions again.
- Data Exfiltration: This 7-second window is sufficient. The attacker can repeat the procedure indefinitely to extract the entire disk contents in chunks, as MTP supports partial file transfers.
This attack was responsibly disclosed to Google, who assigned a CVE (details not specified) and released a patch in the November 2024 Android security update. It highlights how seemingly innocuous timeout mechanisms, combined with specific user configurations and reachable code paths, can lead to severe security bypasses.
Demo / Proof of Concept
▶ Watch: Introducing the malicious phone charger attack scenario (6:00)
The researchers provided compelling video demonstrations for each of their primary attack findings, showcasing their real-world impact on vulnerable devices.
- Android Open Accessory Protocol (AAP) Bypass Demo (Malicious Charger):
This demonstration was performed on a recent Samsung device. The video highlighted the speed and stealth of the attack. When the victim device was connected to the malicious charger, the user consent dialogue for MTP access appeared for only a "few seconds" – a "short flickering" – before being autonomously confirmed by the charger's injected input events via AAP. From that point, the malicious charger gained full, stealthy access to all files on the device, without any meaningful user interaction or consent.
- Huawei Data Truncation Demo (Locked Device):
This demo illustrated the destructive potential of the MTP customization vulnerability on an unpatched Huawei device. The video began by showing the device containing various images. The device was then locked and connected to a computer running the attack script. Critically, the device remained locked throughout the attack. After the script completed, the device was unlocked with its PIN. Upon refreshing the file browser, all the original images were gone. The researchers explained that the files themselves were still listed by name, but their contents had been truncated to zero bytes, effectively erasing all user data without the device ever being unlocked by the user during the attack.
- Android USB Manager Timeout Attack Demo (Locked Device Full MTP Access):
The final demonstration showcased the USB Manager timeout attack on a Pixel 8 running a vulnerable Android 15 build. The demo started with a fresh picture of a kangaroo being taken on the device. The device was then locked, requiring the screen unlock PIN for access. The locked device was connected to a computer, and it remained locked for the entire duration of the attack. The attacker's script successfully extracted a list of files from the locked device. Following this, the script proceeded to extract the actual file contents of the most recent file—the kangaroo picture—demonstrating full MTP access to user data on a completely locked and unauthenticated device. The ability to extract specific file contents proved the efficacy of the repeated 7-second MTP access windows.
These demonstrations provided clear visual evidence of the attacks, underscoring their effectiveness against both the user consent model and the perceived security of a locked device.
Defensive Implications
▶ Watch: Malicious charger attack using Bluetooth and PD swaps (8:00)
The findings presented by Rasha and Ma have significant implications for mobile device manufacturers, operating system developers, and end-users, highlighting areas where current security practices need urgent revision.
For device manufacturers and OS developers, the immediate defensive action involves patching the disclosed vulnerabilities. The researchers reported that affected vendors have already patched the physical access scenarios, and Google assigned CVEs for the Android USB Manager timeout attack (patched in the November 2024 Android security update) and addressed the malicious charger attacks in AOSP. Apple also assigned a CVE and mitigated the Bluetooth-based malicious charger attack in iOS 18.4.
Beyond immediate patches, the talk emphasizes the need for a fundamental revision of USB trust models. The fact that Android 15 and iOS 18.4 now explicitly require user authentication before USB file access can be enabled indicates a shift towards a more robust security posture. However, a significant challenge remains for the Android ecosystem: fragmentation. Given the high degree of customization across different Android manufacturers, it is "unclear whether all Android manufacturers actually integrate these fixes," potentially leaving a large installed base vulnerable.
The concept of lockdown or restricted modes in recent Android and iOS versions is a promising defensive measure. These modes are designed as "improved, hardened lock screens" that are supposed to entirely disable the USB hardware of the device, effectively cutting off the attack vector. However, the adoption of this feature on Android is "rather slow" because it requires considerable effort from individual vendors to integrate these changes into their low-level USB stacks. Furthermore, even these improved modes are not entirely foolproof. The researchers themselves found a CVE (details not specified) affecting the iOS restricted mode, demonstrating that even hardened features can have bypasses.
For end-users, the researchers provide several actionable recommendations:
- Install operating system updates immediately: This is the most critical defense, as it ensures that known vulnerabilities, like those disclosed in the talk, are patched.
- Bring your own power bank: To avoid relying on potentially compromised public charging infrastructure (e.g., at airports, hotels, or public rental chargers), carrying a personal power bank is strongly advised.
- Shut down your device when using public charging infrastructure: If using a public charger is unavoidable, shutting down the device ensures that its file encryption capabilities are fully active. For Android devices, files are only encrypted after a reboot and until the user first enters their unlock PIN or presents a fingerprint. A locked but powered-on device with "credential encrypted storage" remains accessible if it has been unlocked at least once since the last reboot. Shutting down completely prevents this.
- Watch your phone, don't hand it to strangers, and only use trusted chargers: Basic physical security and vigilance remain paramount.
In essence, while OS vendors are moving towards stronger USB trust models and hardened lock screens, the pace of adoption and the persistence of subtle flaws mean that both technical defenses and user awareness are crucial for safeguarding mobile device data.
Key Takeaways
- "Juice jacking" is not dead: Malicious chargers can still extract files over USB, bypassing existing user confirmation prompts through sophisticated techniques. These are better described as "choice jacking" attacks, as they autonomously accept user prompts.
- Locked devices are not always secure: File extraction and even data destruction (truncation) are possible on physically locked, state-of-the-art mobile devices and operating system versions, challenging the assumption that a locked screen fully protects data.
- Vendor customizations introduce risk: Deviations from standard AOSP security implementations, as seen in the Huawei case, can introduce critical vulnerabilities that bypass intended security mechanisms.
- OS and hardware interactions are complex: Subtle flaws in USB state machines and timeout handlers, combined with user-configurable settings, can create windows for unauthorized data access.
- User vigilance is critical: Users must adopt proactive security habits, including promptly installing OS updates, using personal power banks, shutting down devices when charging publicly, and exercising caution with unfamiliar chargers and physical access.
About the Speaker(s)
Floren Rasha is a PhD student at GR University of Technology. His research focuses on various aspects of mobile security, contributing to a deeper understanding of vulnerabilities and defenses in the mobile ecosystem.
Lucas Ma is a PhD candidate at K University of Technology. His research area is system security, with a particular emphasis on kernel and side-channel security. His expertise in low-level system interactions was instrumental in uncovering the intricate USB-based vulnerabilities presented in this talk.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
Rasha and Ma delivered a crushing blow to mobile security assumptions, demonstrating multiple novel USB-based attacks that bypass user consent and even extract data from locked iOS and Android devices. This isn't your grandad's 'juice jacking'; it's 'choice jacking' and full data exfiltration on devices users thought were secure. The work is technically deep, impactful, and clearly the result of genuine, difficult research. It forces a fundamental re-evaluation of USB trust models and reminds everyone that physical access and subtle protocol flaws remain critical vectors.
Heather Calloway (CISO) — MUST SEE
This presentation by Rasha and Ma is a critical examination of mobile device security, revealing how both malicious chargers and physical access to locked devices can bypass established security controls on iOS and Android. Their research meticulously demonstrates "choice jacking" attacks that circumvent user consent prompts and exposes vulnerabilities that allow data extraction and destruction on locked devices. The findings demand an immediate re-evaluation of mobile device trust models, highlighting significant risks for organizational data governance and necessitating revised operational policies for mobile fleet management and user education.