{"id":33356,"date":"2025-07-30T12:07:11","date_gmt":"2025-07-30T12:07:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/33356\/"},"modified":"2025-07-30T12:07:11","modified_gmt":"2025-07-30T12:07:11","slug":"psa-new-choicejacking-attacks-can-steal-your-android-or-iphones-data-without-your-knowledge","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/33356\/","title":{"rendered":"PSA: New &#8216;choicejacking&#8217; attacks can steal your Android or iPhone&#8217;s data without your knowledge"},"content":{"rendered":"<p><img class=\"e_Kg\" decoding=\"async\" loading=\"eager\"  title=\"USB stick plugged into an Android phone while locked hero image\"  alt=\"USB stick plugged into an Android phone while locked hero image\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/07\/USB_stick_plugged_into_an_Android_phone_while_locked_hero_image-scaled.jpg\"\/><\/p>\n<p>Mishaal Rahman \/ Android Authority<\/p>\n<p>TL;DR<\/p>\n<p>Researchers have identified new methods to exploit backdoors into Android and iOS to steal data.<br \/>\n\u201cChoicejacking\u201d is an evolution of the infamous juice jacking technique and also uses a rigged USB charger or cable to initiate data theft on your mobile devices.<br \/>\nChoicejacking uses a combination of techniques to bypass existing juice jacking protection while faking user input to enable permissions illicitly.<\/p>\n<p>Juice jacking is a decade-old technique where hackers can install spyware and gain access to your phone when you use a public charging point to juice up (hence, the name) the phone\u2019s battery. Over the years, Google and Apple have enforced restrictions that prevent data transfer, especially when your phone is locked. Although these measures have been believed to suffice, researchers recently discovered they may not be enough, primarily in the face of more sophisticated attacks.<\/p>\n<p>Researchers at TU Graz, Austria, recently identified a series of novel techniques that can bypass existing preventive restrictions and access data on anyone\u2019s iPhone or Android device using the USB port. They have named the new technique \u201cChoice-jacking,\u201d a wordplay on the familiar technique of <a href=\"https:\/\/www.androidauthority.com\/what-is-juice-jacking-3460519\/\" rel=\"nofollow noopener\" target=\"_blank\">juice jacking<\/a>. In the <a href=\"https:\/\/tugraz.elsevierpure.com\/ws\/portalfiles\/portal\/89650227\/Final_Paper_Usenix.pdf\" target=\"_blank\" rel=\"nofollow noopener\">paper<\/a>, researchers claim they were able to spoof user actions, such as actively switching from just charging to data transfer and allowing a prompt that enables an external system or device to access files and settings on your phone. The nature attack involves replicating user choices, which could have led to the naming.<\/p>\n<p>Like juice jacking, choicejacking uses malicious chargers to initiate attacks on the users\u2019 phones. Unlike connections to PCs, both Android and iOS allow direct access to wired accessories without explicit permission, which can be exploited for attacks.<\/p>\n<p>On Android, specifically, the attacks work by exploiting permissions for peripherals (via AOAP or Android Open Accessory Protocol), such as <a href=\"https:\/\/www.androidauthority.com\/best-travel-mice-3034177\/\" rel=\"nofollow noopener\" target=\"_blank\">mice<\/a> or keyboards. Attackers can then begin hijacking system input through ADB (or Android Debug Bridge), which can simulate user input and change the USB mode to allow data transfer. The attack then proceeds with a series of commands aimed at gaining complete control of the device and gaining key access for further control.<\/p>\n<p>On iOS, a rigged USB cable or charger can be used to trigger a connection event for a Bluetooth device. Although it may appear as a regular Bluetooth-based audio accessory to your iPhone, it could act as the machinery to secretly allow data transfer and gain access to specific files and photos. However, it cannot access the entire iOS system as it can on Android.<\/p>\n<p>The team says it tested these attacks on eight top phone brands, including Xiaomi, Samsung, Google, Apple, etc. It notified these brands, and six out of eight have already patched \u2014 or are in the process of patching \u2014 the vulnerability.<\/p>\n<p>Despite these fixes, the best defense against choicejacking would be to avoid using public chargers at all costs. If you\u2019re traveling or anticipate your phone\u2019s battery may not last through the duration that you are out, we suggest carrying your own solution. There are plenty of <a href=\"https:\/\/www.androidauthority.com\/best-portable-chargers-409078\/\" rel=\"nofollow noopener\" target=\"_blank\">chargers or power banks that we recommend<\/a> so you can avoid attacks like choicejacking and avoid getting malware on your phone, or worse, losing your personal data in the process. Other solutions, such as <a href=\"https:\/\/www.androidauthority.com\/android-15-lockdown-mode-changes-3450855\/\" rel=\"nofollow noopener\" target=\"_blank\">Android\u2019s Lockdown mode<\/a>, could be your saviors, but you would need to activate it manually every time you charge your phone with an unknown charger.<\/p>\n<p>Thank you for being part of our community. Read our\u00a0<a class=\"c-link\" href=\"https:\/\/www.androidauthority.com\/android-authority-comment-policy\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-stringify-link=\"https:\/\/www.androidauthority.com\/android-authority-comment-policy\/\" data-sk=\"tooltip_parent\">Comment Policy<\/a> before posting.<\/p>\n","protected":false},"excerpt":{"rendered":"Mishaal Rahman \/ Android Authority TL;DR Researchers have identified new methods to exploit backdoors into Android and iOS&hellip;\n","protected":false},"author":2,"featured_media":33357,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[2596,20087,12249,59,5215,86,56,54,55,20088,20089],"class_list":["post-33356","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-android","tag-apple-ios","tag-apple-iphone","tag-gb","tag-hacking","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom","tag-usb","tag-usb-c"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/33356","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=33356"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/33356\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/33357"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=33356"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=33356"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=33356"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}