Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»New Android Taptrap attacks users with invisible UI trick
    Security

    New Android Taptrap attacks users with invisible UI trick

    PineapplesUpdateBy PineapplesUpdateJuly 8, 2025No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    New Android Taptrap attacks users with invisible UI trick
    Share
    Facebook Twitter LinkedIn Pinterest Email

    New Android Taptrap attacks users with invisible UI trick

    A novel tapjacking technique can take advantage of the user interface animation to bypass the permission system of Android and allow sensitive data or trick users to perform disastrous actions, such as wipes of the device.

    Unlike traditional, overlay-based tapsacing, the taprap attack also works with zero-parametic applications to launch a harmless transparent activity on top of a malicious one, also with a behavior that remains unmate in Android 15 and 16.

    Taptrap was developed by a team of security researchers at Tu Wien and Bayreth University (Philip Beer, Marco Squarsina, Sebstian Roth, Martina Lindorfer), and will be presented in the next month Usenix Safety Seminar,

    However, the team has already published Technical letter It outlines the attack and A Website It summarizes most of the details.

    How does tiprap work

    TAPTRAP abuses the way android activity handles infections with custom animation that sees the user and the device actually registers.

    A malicious app installed on the target device launches a sensitive system screen (permission Prompt, System Settings, etc.) from another app using ‘Startectivity ()’ with a custom low-opesity animation.

    “The key to the taprap is using an animation that provides the target activity almost invisible,” the researchers said that The website that explains the attack,

    “It can be achieved by defining a custom animation, with both beginners and expired op variety (alpha) a low value, such as 0.01,” thus made malicious or risky activity almost completely transparent.

    “Alternatively, a scale animation can be applied to zoom in a specific UI element (eg, an permission button), allowing it to occupy full screen and increase the opportunity to tap the user.”

    Taporap observation
    Taporap observation
    Source: Taptrap.Click

    Although the prompt a launched prompts receive all the touch events, all the users see that the underlying app shows its own UI elements, as it has a transparent screen on top of which the user is actually attached.

    Thinking that they interact with the Benning app, a user can tap on specific screen positions that suit risky tasks, such as “permission” or “authorized” button on almost invisible signals.

    A video released by the researchers shows how a game app can avail tattrap to enable camera access to a website through Chrome browser.

    Risk risk

    To check if the Tipp Play Store could work with the application in the official Android repository, researchers analyzed around 100,000. They found that 76% of them are insecure for tattrap as they include a screen (“activity”) that meets the following conditions:

    • Can be launched by another app
    • Calling runs in the same task as app
    • Infection does not override to animation
    • User does not wait for animation to end before reacting to input

    Researchers say that animations on the latest Android version are enabled until the user deactivates them with developer options or accessibility settings, exposing the device to tatrapy attacks.

    When developing the attack, the researchers used Android 15, the latest version at that time, but after the arrival of Android 16, they also conducted some tests on it.

    Marco Squarsina told BlappingCopper that she had tried to tippe on Android 16 on Google Pixel 8A and can confirm that the issue is precious.

    Mobile operating system graphinos, which focuses on privacy and security, also confirmed the Blapping computer that the latest Android 16 is unsafe for tattrap technology, and announced that their next release would be Include a fix,

    Bleepingcomputer has approached Google about Taptrap, and a spokesman said that the taprap problem will be reduced in future updates:

    “Android is continuously improving its existing mitigation against tapjacking attacks. We know about this research and we will address the issue in future updates. Google Play has policies to keep users safe, which should follow all developers, and if we find that we have a violation of our policies.”


    Tines needle

    While cloud attacks can be more sophisticated, the attackers still succeed with surprisingly simple techniques.

    Drawing by the detection of Vij in thousands of organizations, this report reveals the 8 major techniques used by Claude-Floid danger actors.

    Android attacks invisible Taptrap trick users
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAmazon Prime Day is here – and the AirCov routers of ExpressVN got 30% discount
    Next Article Samsung Galaxy Z Fold 7 Dosha Bus Just appeared in unpacked leaks in the last minute
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    I wasn’t looking to replace my Kindle, but this Android e-reader made it easy

    January 19, 2026
    Startups

    My 4-step routine to get any Android phone operating like new (and reliably) again

    January 16, 2026
    Startups

    Why I use this $200 Android tablet more than my iPad, and I don’t regret it

    January 15, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Google tests AI-operated audio overview in search results for some questions

    June 16, 20250 Views

    Yes, this was the original voice of the Garat in the trailer for the thief VR

    June 16, 20250 Views

    Best LC10 loadout in call of duty: Warzone

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.