My presentation about StrandHogg and other task hijacking exploitation on Android and their mitigations as presented at next.app devCon / masCon Berlin on October 7, 2026.
Intro
Task hijacking is when a malicious app launches its Activity into the task of another. The trivial counter to the simplest form is to set an empty task affinity for your Activity. That's not all, as the more serious Strandhogg 2.0 exploit doesn't rely on Manifest-based configuration and can dynamically target multiple applications. There is also the fact that the system still allows background apps to launch their Activity on top of others in certain circumstances.
There are mitigations for most attacks on newer Android versions, but if your app needs to be backward compatible, it is entirely on you to apply defense in depth, and I'll show you how, including a quick demo.
Links
Android Security Evolution:
https://github.com/balazsgerlei/AndroidSecurityEvolution
USENIX Security '15 - Towards Discovering and Understanding Task Hijacking in Android:
https://youtu.be/IYGwXFIYdS8
Promon’s blog posts about StrandHogg
https://promon.io/security-news/the-strandhogg-vulnerability
https://promon.io/resources/downloads/strandhogg-2-0-new-serious-android-vulnerability
HackTricks - Android Task Hijacking:
https://book.hacktricks.wiki/en/mobile-pentesting/android-app-pentesting/android-task-hijacking.html
USENIX Security '25 - TapTrap: Animation-Driven Tapjacking on Android
https://youtu.be/dRM5cBu3fJ8
Embedded photo picker
https://developer.android.com/training/data-storage/shared/photo-picker/embedded