daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

android-enterprise-work-profile-bypass.md (5285B)


      1 ---
      2 title: "Android Enterprise Work Profile Required-App Replacement"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/android-app-pentesting/android-enterprise-work-profile-bypass.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/android-enterprise-work-profile-bypass.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Android Enterprise Work Profile Required-App Replacement
     14 
     15 ## Attack surface
     16 
     17 Android Enterprise Work Profiles are implemented as **secondary Android users** (BYOD example: user `0` = personal, user `1` = work). Each user has independent `/data/user/<id>` trees, system apps, Play Services instances and policy objects maintained by the MDM. When an MDM such as **Microsoft Intune** marks an app as *required* for the Work Profile, the **Work-Profile Play Store (Finsky)** periodically confirms the package is present and auto-installs it if missing.<sup>[[1]](#references)</sup>
     18 
     19 Even after the **CVE-2023-21257** patch that blocks ADB sideloads when `DISALLOW_INSTALL_APPS` or `DISALLOW_DEBUGGING_FEATURES` are set, the following chain lets an attacker **replace any Intune-required Work Profile app** with arbitrary code:<sup>[[1]](#references)</sup>
     20 
     21 1. Abuse Android Studio's **"Install for all users"** path to stage a malicious APK that looks like an update of the managed package.
     22 2. Let the MDM notice the required app is missing. Intune triggers the Work-Profile Finsky instance to reinstall it.
     23 3. Finsky compares the staged APK version with the Play Store version and silently installs the **highest `versionCode`**, bypassing the original restriction.
     24 
     25 ## Recon and prerequisite checks
     26 
     27 * Confirm multi-user layout and user IDs:<sup>[[1]](#references)</sup>
     28 
     29 ```bash
     30 adb shell pm list users
     31 # Expect user 0 = Owner, user 1 = Work profile (or higher if multiple profiles exist)
     32 ```
     33 
     34 * Direct installs into the work user fail under policy (expected error):
     35 
     36 ```bash
     37 adb install --user 1 legit.apk
     38 # java.lang.SecurityException: Shell does not have permission to access user 1
     39 ```
     40 
     41 * You must have **temporary physical access to an unlocked BYOD** to enable Developer Options + USB debugging.<sup>[[1]](#references)</sup>
     42 * Identify the **package name** of a Work-Profile app marked as *required* (e.g. `com.workday.workdroidapp`).
     43 
     44 ## Weaponising the Android Studio multi-user installer
     45 
     46 Android Studio's Run/Debug configuration can still push builds with the **`INSTALL_ALL_USERS`** flag. Before running, enable *Deploy as instant app* → *Install for all users*.<sup>[[1]](#references)</sup>
     47 
     48 Build the malicious payload with the **same package name** as the managed app and a **much larger `versionCode`** so PackageManager/Finsky treats it as a newer release:<sup>[[1]](#references)</sup>
     49 
     50 ```text
     51 android {
     52     namespace = "com.workday.workdroidapp"
     53     defaultConfig {
     54         applicationId = "com.workday.workdroidapp"
     55         versionCode = 900000004
     56         versionName = "9000000004.0"
     57     }
     58 }
     59 ```
     60 
     61 When Android Studio deploys:<sup>[[1]](#references)</sup>
     62 
     63 1. **Personal user (0)** installs the malicious package normally.
     64 2. **Work Profile user (1)** receives the APK in a temporary staging area and tries to treat it as an update.
     65 3. CVE-2023-21257's logic sees the user is restricted → **install is denied**, but the legitimate managed app is marked uninstalled and the staged APK remains cached.
     66 
     67 ## Intune/Finsky auto-install bypass
     68 
     69 Within ~1–10 minutes (policy refresh interval):<sup>[[1]](#references)</sup>
     70 
     71 1. Intune/Company Portal detects the *required* package is missing from the Work Profile.
     72 2. The Work-Profile **Finsky** instance is asked to reinstall it.
     73 3. During version resolution Finsky compares:
     74    * Play Store metadata for `com.workday.workdroidapp`.
     75    * The locally staged APK from the previous install attempt.
     76 4. Because the local build has the **highest `versionCode`**, Finsky trusts it as the most recent release and installs it into the restricted Work Profile **without re-applying `DISALLOW_INSTALL_APPS` / `DISALLOW_DEBUGGING_FEATURES` checks**.
     77 
     78 The malicious binary now resides inside the Work Profile under the genuine package name and is considered compliant by the MDM.<sup>[[1]](#references)</sup>
     79 
     80 ## Post-exploitation opportunities
     81 
     82 * **Work-profile data access** – other enterprise apps keep trusting Intents/content providers bound to the replaced package, enabling internal data theft and covert exfiltration from the Work Profile to attacker infrastructure.<sup>[[1]](#references)</sup>
     83 * **Per-app VPN hijack** – if the replaced package is mapped to an Intune per-app VPN (MS Tunnels + Defender), the malicious build automatically inherits the VPN profile, giving direct access to internal hosts from an attacker-controlled process.
     84 * **Persistence** – because the MDM now believes the required app is installed, it will **reinstall the malicious build** whenever the user or defender removes it, providing long-term foothold on BYOD Work Profiles.
     85 
     86 ## References
     87 
     88 - [1] [Bypassing CVE-2023-21257 via Intune Required-App Auto-Install](https://jgnr.ch/sites/android_enterprise.html)