'Institute of Electrical and Electronics Engineers (IEEE)'
Abstract
Recent studies have determined that many Android applications in both official and non-official online markets expose details of the users\u27 smartphones without user consent. In this paper, we explain why such applications leak, how they leak and where the data is leaked to. In order to achieve this, we combine static and dynamic analysis to examine Java classes and application behaviour for a set of popular, clean applications from the Finance and Games categories. We observed that all the applications in our data set which leaked information (10%) had third-party advertising libraries embedded in their respective Java packages