An Empirical Study on Fingerprint API Misuse with Lifecycle Analysis in Real-world Android Apps
Xin Zhang
Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Android Security 2
Overview
This talk, presented by Xin Zhang from Fudan University, delves into the pervasive security vulnerabilities stemming from the misuse of Fingerprint-Based Authentication (FBO) APIs in real-world Android applications. As FBO becomes a ubiquitous security feature, integrated into sensitive scenarios like account logins, app unlocking, and payment authorizations, its secure implementation is paramount. The research highlights that despite its convenience, the underlying Android APIs are complex and frequently mishandled by developers, leading to significant security risks.
Key moments
- 0:00 Introduction: Fingerprint API complexity and misuse problem
- 2:00 Novel approach: Fingerprint API misuse via lifecycle analysis
- 2:40 Overview of four common fingerprint API misuse types
- 4:00 Mishandled fingerprint updates: Threat model and attack scenario
- 5:30 Automated detection: Static analysis tool and methodology
- 6:40 Alarming findings: 97% of apps contain at least one misuse
- 7:50 Real-world example: WhatsApp vulnerable to deactivation misuse
- 9:45 Conclusion: Summary of findings and need for secure API usage
An Empirical Study on Fingerprint API Misuse with Lifecycle Analysis in Real-world Android Apps
Speakers: Xin Zhang
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=8BIAK3uEr0g
Overview
This talk, presented by Xin Zhang from Fudan University, delves into the pervasive security vulnerabilities stemming from the misuse of Fingerprint-Based Authentication (FBO) APIs in real-world Android applications. As FBO becomes a ubiquitous security feature, integrated into sensitive scenarios like account logins, app unlocking, and payment authorizations, its secure implementation is paramount. The research highlights that despite its convenience, the underlying Android APIs are complex and frequently mishandled by developers, leading to significant security risks.
The core contribution of this study is its novel lifecycle analysis approach to FBO, moving beyond the traditional focus on just the verification stage. By examining the entire FBO lifecycle—including activation, verification, fingerprint updates, and deactivation—the researchers uncovered new threat models and previously overlooked security issues. Their large-scale empirical study on over a thousand Android apps reveals a concerning landscape: nearly 97% of FBO-enabled applications contain at least one type of critical misuse, making billions of installations potentially vulnerable to various forms of attack, ranging from local software-level exploits to physical device compromise.
The findings underscore a critical gap between the intended secure design of Android's FBO framework and its practical implementation by developers. The complexity of the APIs, which span five function groups and have undergone significant evolution, often results in developers making choices that prioritize functionality or convenience over robust security. This article will dissect the methodologies, key findings, and defensive implications of this important research, offering a comprehensive understanding of the challenges and necessary improvements in Android FBO security.
Background
▶ Watch: Introduction: Fingerprint API complexity and misuse problem (0:00)
Fingerprint-Based Authentication (FBO) has become a cornerstone of modern mobile security, offering a convenient yet seemingly robust method for users to secure their devices and applications. The underlying process involves several critical steps: a user's fingerprint is scanned by a sensor, the data is then securely compared within the Trusted Execution Environment (TE)—an isolated, secure area within the device—which subsequently relays the verification result to the application via Android's specialized fingerprint APIs. Crucially, cryptographic keys can be integrated into this process to ensure the integrity and authenticity of the verification result, adding an extra layer of security.
However, the implementation of FBO by developers is far from straightforward. Android's fingerprint APIs are notoriously complex, encompassing five distinct function groups and having undergone substantial changes across different Android versions. This inherent complexity creates a fertile ground for developer error and misuse, leading to vulnerabilities. Previous academic and industry research on FBO security has predominantly concentrated on the verification stage, examining how fingerprints are matched and the results communicated. While important, this narrow focus has left other critical phases of the FBO process largely unexamined.
This study introduces a new, holistic perspective: a lifecycle analysis of FBO. The researchers define the FBO lifecycle as comprising four key stages:
- Activation: The initial setup of fingerprint authentication within an app.
- Verification: The ongoing process of authenticating a user via their fingerprint.
- Fingerprint Update: Scenarios where users add or remove fingerprints from their device settings.
- Deactivation: The process of disabling fingerprint protection within an application.
By systematically examining the entire lifecycle, the research aims to uncover security issues in often-overlooked stages. Building upon prior work, the study investigates four distinct types of fingerprint API misuses. The first two, obsolete API usage and inadequate cryptographic validation, have been partially explored in previous research concerning the verification stage. The latter two, unauthorized fingerprint deactivation and mishandled fingerprint updates, represent newly identified threat models and are central to the novel contributions of this paper, highlighting vulnerabilities that emerge from a complete lifecycle perspective.
Key Findings
▶ Watch: Overview of four common fingerprint API misuse types (2:40)
The empirical study conducted by Xin Zhang and his team provides a sobering assessment of fingerprint API misuse in real-world Android applications. Their large-scale analysis involved scrutinizing approximately 65,000 apps sampled from Google Play and Huawei app markets. Out of this vast dataset, they identified 1,333 apps that actively utilize FBO, collectively boasting over 218 billion installations—a testament to the widespread impact of any security flaws within these applications.
The overarching finding is alarming: almost all FBO-enabled apps, a staggering 97%, contain at least one type of the identified misuses. Furthermore, each specific category of misuse was found to be present in nearly or over half of these FBO applications, indicating a systemic problem rather than isolated incidents.
Specific findings for each misuse type include:
- Obsolete API Usage: Even five years after the introduction of more secure and robust FBO APIs, nearly half of the analyzed apps continue to rely solely on the older, unsecure APIs. This persistent use leaves them vulnerable to well-known attacks, such as UI hijacking.
- Inadequate Cryptographic Validation: While this type of misuse was partially explored by prior work (e.g., "Broken Fingers" at NDSS 2018), this study measured its current prevalence. The general finding that "each type of misuse is present in nearly or over half of the FP of app" applies here, indicating that a significant portion of apps fail to correctly bind cryptographic keys to the FBO process, leading to unreliable verification results susceptible to OS-level attackers with root privileges.
- Unauthorized Fingerprint Deactivation: The research identified 120 apps that exhibit a critical logical flaw: they correctly enforce fingerprint authentication when activating FBO protection but fail to require any authentication when deactivating it. This renders the protection ineffective, as an attacker with brief physical access to an unlocked device can permanently disable FBO. A notable example cited was WhatsApp, which requires FBO for activation and re-authentication upon returning from the background, yet allows deactivation of the fingerprint lock without any further authentication.
- Mishandled Fingerprint Updates: This newly identified misuse is tied to how apps interact with system-level fingerprint enrollment changes. The study uncovered instances where developers either intentionally or unintentionally ignore these updates. For example, 17 apps that otherwise do not allow PIN as an alternative authentication method were found to deliberately ignore fingerprint updates, compromising security. Even more concerning, five apps demonstrated a fundamental lack of security knowledge, attempting to configure invalidation upon fingerprint updates but then nullifying this security intention by misconfiguring other related APIs. This misuse degrades the security model from a strong two-factor authentication (fingerprint + PIN) to a weaker one-factor authentication (just PIN), making it susceptible to attackers who know the victim's PIN.
The real-world impact of these findings is substantial. The researchers responsibly reported these issues to vulnerability databases and developers, resulting in the assignment of 184 CVE IDs (Common Vulnerabilities and Exposures), underscoring the severity and widespread nature of the identified flaws.
Technical Deep Dive
▶ Watch: Automated detection: Static analysis tool and methodology (5:30)
The study's technical depth lies in its systematic approach to identifying and categorizing fingerprint API misuses across the entire FBO lifecycle, coupled with a custom static analysis tool designed to detect these patterns at scale.
The four primary types of FBO API misuses are:
- Obsolete API Usage: This misuse concerns applications that continue to use deprecated or less secure versions of Android's FBO APIs. Specifically, the talk references the "Feedjacking" work presented at NDSS 2022, which demonstrated that apps relying on these older APIs are vulnerable to UI hijacking attacks. In such an attack, a local malicious app or SDK can overlay or manipulate the user interface during the fingerprint authentication prompt, effectively "jacking" the user's fingerprint input without their knowledge or consent. Newer APIs offer enhanced security features, including stronger UI protections and better integration with cryptographic operations, which are absent in their predecessors.
- Inadequate Cryptographic Validation: This vulnerability, initially highlighted by "Broken Fingers" at NDSS 2018, targets a local OS-level attacker with root privileges. The core issue is the failure to correctly bind cryptographic keys to the FBO process. When an application initiates a fingerprint authentication, it can optionally provide a
CipherorMacobject (cryptographic primitives) to the API. If the fingerprint verification is successful, the API signs a challenge using a key bound to the user's enrolled fingerprints within the TE. The app should then validate this signature using the providedCipherorMac. Failing to perform this cryptographic binding, or incorrectly validating the result, means the app cannot reliably trust the FBO verification result. A rooted attacker could potentially bypass the FBO result reported by the system, falsely indicating success even if the fingerprint scan failed, thus granting unauthorized access.
- Unauthorized Fingerprint Deactivation: This newly identified misuse exploits a critical logical flaw in how apps handle the disabling of FBO. The attack scenario involves a physical "purist" attacker who gains brief access to the victim's unlocked device. Many sensitive apps correctly require fingerprint authentication when the user activates FBO protection. However, a significant number of apps fail to enforce the same re-authentication requirement when a user attempts to deactivate FBO. In such cases, the attacker can navigate to the app's settings, disable fingerprint protection without needing the victim's fingerprint, and then gain permanent unauthorized access. The example of WhatsApp, which requires FBO on activation and re-entry from background, yet allows deactivation without re-authentication, perfectly illustrates this oversight.
- Mishandled Fingerprint Updates: This is another novel misuse that arises when an app fails to correctly respond to changes in the device's enrolled fingerprints. The Android framework provides mechanisms for apps to be notified of such changes. The attack scenario here considers an attacker who knows the victim's locking screen PIN. While a PIN is generally considered a weaker authentication factor (vulnerable to shoulder surfing, guest attacks, social engineering), it is often required by the system to add or remove fingerprints. If an attacker knows the PIN, they can add their own fingerprint or remove all existing ones from the device settings. A securely implemented app should detect these system-level fingerprint changes and, crucially, invalidate any existing FBO sessions or bound cryptographic keys. If the app fails to do so, the attacker, after modifying the enrolled fingerprints, can then bypass the app's fingerprint authentication using their newly enrolled fingerprint or by exploiting the invalidated state. This effectively degrades the security model from a strong two-factor protection (fingerprint + PIN, where PIN protects changes to the fingerprint) to just a one-weak-factor protection (the PIN itself), as the fingerprint check can now be bypassed.
The technical detection of these misuses was achieved through a custom static analysis tool. This tool operates in three main steps:
- App Intention Distinction: Recognizing that apps may have different security requirements and intentions for FBO (e.g., login vs. payment), the tool first distinguishes these intentions. This context helps in accurately identifying misuse patterns relevant to the app's specific use case.
- Key Stage Identification: The tool identifies the critical FBO lifecycle stages (activation, verification, fingerprint update, deactivation) by analyzing relevant UI components (e.g., buttons, settings menus) and API calls associated with these actions. This allows it to trace the flow of control and data related to FBO.
- Misuse Pattern Mapping: Finally, the static analysis engine maps the app's compiled code against seven predefined misuse patterns. While the talk doesn't list all seven explicitly, they logically correspond to the four discussed misuse types and their variations (e.g., different ways an app might fail to invalidate crypto or handle updates). By identifying specific API calls, their parameters, and the logical flow around them, the tool can pinpoint instances where developers have deviated from secure implementation practices. For instance, the mishandled fingerprint updates misuse is directly related to two key APIs:
setUserAuthenticationRequired(which binds crypto to the app) andsetInvalidateOnBiometricEnrollment(which configures crypto invalidation upon fingerprint updates). The tool checks if these APIs are used correctly and consistently.
This sophisticated static analysis approach enabled the researchers to automatically and accurately detect these complex misuses across a massive dataset of real-world applications, providing empirical evidence for the widespread nature of these vulnerabilities.
Demo / Proof of Concept
▶ Watch: Alarming findings: 97% of apps contain at least one misuse (6:40)
While the talk didn't feature a live, interactive demonstration of an exploit, it provided clear and compelling illustrative examples to explain the impact of the identified misuses. The most prominent example used to articulate the "Unauthorized Fingerprint Deactivation" misuse was the popular messaging application WhatsApp.
The speaker detailed how WhatsApp, in its implementation, correctly requires fingerprint authentication when a user initially activates the fingerprint lock feature. Furthermore, it demands re-authentication every time the user returns to the app from the background, reinforcing its security posture during active use. However, the critical flaw demonstrated was that if an attacker were to gain temporary physical access to the victim's unlocked device, they could navigate to WhatsApp's security settings and disable the fingerprint lock without being prompted for any authentication. This allows the attacker to obtain permanent, unauthorized access to the victim's WhatsApp account, effectively bypassing the security measure that was meant to protect it. This example effectively served as a conceptual proof of concept, highlighting a real-world application exhibiting a severe logical flaw in its FBO lifecycle management.
Similarly, for the "Mishandled Fingerprint Updates" misuse, the talk described an attack scenario where a thief, having obtained the victim's locking PIN, could add their own fingerprints or remove existing ones from the device. If the sensitive app then fails to invalidate its FBO state, the thief can bypass the app's fingerprint authentication to, for instance, make payments or steal money. These scenarios, though not live code demonstrations, effectively convey the practical implications and severity of the vulnerabilities discovered.
Defensive Implications
▶ Watch: Conclusion: Summary of findings and need for secure API usage (9:45)
The findings from this empirical study present critical insights for Android developers, security architects, and platform providers to enhance the security of Fingerprint-Based Authentication. The widespread misuse observed necessitates a fundamental shift in how FBO is implemented and understood.
- Prioritize Secure API Usage: Developers must immediately cease using obsolete FBO APIs. They should migrate to the latest, most secure versions of Android's Biometric APIs (e.g.,
BiometricPromptintroduced in Android 9 Pie) which offer enhanced security features, better UI protection, and more robust cryptographic integration. Regular review of Android's official security guidance for biometric authentication is crucial.
- Mandatory Cryptographic Binding: For any sensitive operation protected by FBO—such as logging into an account, authorizing payments, or accessing confidential data—developers must integrate cryptographic keys into the authentication process. This involves using
setUserAuthenticationRequiredand providing aCipherorMacobject to the FBO API. Crucially, the application must then validate the cryptographic signature returned by the FBO API to ensure the authenticity and integrity of the verification result. This prevents OS-level attackers from fabricating successful authentication outcomes.
- Enforce Re-authentication for Deactivation: Applications must enforce a consistent security policy across the entire FBO lifecycle. If fingerprint authentication is required to activate a security feature, it should **absolutely be required to deactivate it**. This prevents attackers with temporary access to an unlocked device from easily disabling security protections and gaining permanent access. Developers should treat deactivation as a highly sensitive operation akin to changing a password.
- Proper Handling of Fingerprint Updates: Developers must account for system-level changes to enrolled fingerprints. Applications should utilize the appropriate APIs (e.g.,
setInvalidateOnBiometricEnrollmentwhen setting up cryptographic keys) to ensure that any cryptographic keys bound to FBO are automatically invalidated if new fingerprints are enrolled or existing ones are removed from the device. If an app relies onsetInvalidateOnBiometricEnrollmentbeing set totrue, it is paramount to ensure that other API configurations do not inadvertently nullify this security intention. This prevents attackers who know the device PIN from adding their own fingerprints and bypassing app-level FBO.
- Developer Education and Best Practices: The study highlights a significant gap in developer understanding of FBO API complexities and security implications. Platform providers like Google should provide clearer, more prescriptive guidelines and code examples for secure FBO implementation across all lifecycle stages. Developers, in turn, must invest in understanding these best practices, recognizing that fingerprint authentication, while convenient, is a critical security mechanism that, when misused, can severely weaken an app's overall security posture. As emphasized by the speaker, fingerprint authentication, when properly implemented, is considered a stronger authentication factor than a simple PIN in many security models.
By adopting these defensive measures, developers can significantly mitigate the widespread vulnerabilities identified in the study, moving towards a more secure and trustworthy mobile application ecosystem.
Key Takeaways
- Pervasive Misuse: A staggering 97% of Android apps using Fingerprint-Based Authentication (FBO) contain at least one serious security misuse, affecting billions of installations.
- Lifecycle Vulnerabilities: The study’s novel lifecycle analysis approach (activation, verification, update, deactivation) uncovered new threat models and critical vulnerabilities beyond just the verification stage.
- Four Core Misuse Types: The research detailed four common misuses: obsolete API usage, inadequate cryptographic validation, unauthorized fingerprint deactivation, and mishandled fingerprint updates.
- Critical Impact: These misuses enable various attacks, from UI hijacking and OS-level root bypasses to physical device compromise and degradation of two-factor authentication to a weaker single factor.
- Developer Responsibility: Developers must prioritize security over convenience, adopt the latest Biometric APIs, consistently enforce re-authentication for deactivation, and correctly manage cryptographic key invalidation upon system fingerprint updates.
- Real-world Validation: The findings led to the assignment of 184 CVE IDs, confirming the practical severity and widespread nature of these FBO implementation flaws.
About the Speaker(s)
Xin Zhang is a researcher affiliated with Fudan University. His work focuses on mobile security, particularly the empirical study of vulnerabilities in widely used mobile technologies like Fingerprint-Based Authentication in Android applications. His research contributes to identifying critical security flaws and advocating for more robust and secure development practices in the mobile ecosystem.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Solid empirical security research with a genuinely novel contribution: the lifecycle framing of FBO misuse that surfaces two new attack classes (unauthorized deactivation, mishandled enrollment updates) that prior work missed entirely. 184 CVEs across a 1,333-app corpus is not a theoretical exercise — that's real damage quantified at scale.
Heather Calloway (CISO) — WEAK
Solid academic work with real CVE output — 184 identifiers and a 97% misuse rate across apps with billions of installs is not a trivial finding. But this talk stops at the vulnerability catalog. It never crosses into the questions that matter at the governance and program level: who is accountable for API misuse at scale, what does a platform owner owe its developers, and what should a CISO actually do differently tomorrow.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025