Researchers Reveal Critical Flaws in Mobile Juice Jacking Defenses Exploited by ChoiceJacking Attack
A new attack called ‘ChoiceJacking’ has been revealed by researchers from Graz University of Technology, showing that long-standing defenses in iOS and Android against juice jacking have been fundamentally flawed. Juice jacking involves malicious chargers that secretly access and steal data from connected phones. Despite Apple and Google introducing confirmation prompts over a decade ago to mitigate such risks, the new research demonstrates that these measures could be bypassed by spoofing user input. The researchers developed three attack techniques, exploiting the trust models of USB connections, allowing malicious chargers to inject input events and gain unauthorized access to sensitive data. Apple addressed the issue in iOS/iPadOS 18.4 by requiring user authentication for data access, while Google made similar improvements in Android 15. However, due to Android’s ecosystem fragmentation, many devices from manufacturers like Samsung remain vulnerable. One attack uses USB and Bluetooth trickery to both spoof input and switch device roles; another abuses protocol implementation flaws, and a third leverages race conditions in Android’s event queue. Devices with USB Debugging enabled are especially at risk. While no real-world attacks have been reported, experts recommend avoiding public chargers and using data blockers despite their charging limitations.
