android-enterprise-work-profile-bypass.md (5285B)
1 --- 2 title: "Android Enterprise Work Profile Required-App Replacement" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/android-app-pentesting/android-enterprise-work-profile-bypass.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/android-enterprise-work-profile-bypass.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Android Enterprise Work Profile Required-App Replacement 14 15 ## Attack surface 16 17 Android Enterprise Work Profiles are implemented as **secondary Android users** (BYOD example: user `0` = personal, user `1` = work). Each user has independent `/data/user/<id>` trees, system apps, Play Services instances and policy objects maintained by the MDM. When an MDM such as **Microsoft Intune** marks an app as *required* for the Work Profile, the **Work-Profile Play Store (Finsky)** periodically confirms the package is present and auto-installs it if missing.<sup>[[1]](#references)</sup> 18 19 Even after the **CVE-2023-21257** patch that blocks ADB sideloads when `DISALLOW_INSTALL_APPS` or `DISALLOW_DEBUGGING_FEATURES` are set, the following chain lets an attacker **replace any Intune-required Work Profile app** with arbitrary code:<sup>[[1]](#references)</sup> 20 21 1. Abuse Android Studio's **"Install for all users"** path to stage a malicious APK that looks like an update of the managed package. 22 2. Let the MDM notice the required app is missing. Intune triggers the Work-Profile Finsky instance to reinstall it. 23 3. Finsky compares the staged APK version with the Play Store version and silently installs the **highest `versionCode`**, bypassing the original restriction. 24 25 ## Recon and prerequisite checks 26 27 * Confirm multi-user layout and user IDs:<sup>[[1]](#references)</sup> 28 29 ```bash 30 adb shell pm list users 31 # Expect user 0 = Owner, user 1 = Work profile (or higher if multiple profiles exist) 32 ``` 33 34 * Direct installs into the work user fail under policy (expected error): 35 36 ```bash 37 adb install --user 1 legit.apk 38 # java.lang.SecurityException: Shell does not have permission to access user 1 39 ``` 40 41 * You must have **temporary physical access to an unlocked BYOD** to enable Developer Options + USB debugging.<sup>[[1]](#references)</sup> 42 * Identify the **package name** of a Work-Profile app marked as *required* (e.g. `com.workday.workdroidapp`). 43 44 ## Weaponising the Android Studio multi-user installer 45 46 Android Studio's Run/Debug configuration can still push builds with the **`INSTALL_ALL_USERS`** flag. Before running, enable *Deploy as instant app* → *Install for all users*.<sup>[[1]](#references)</sup> 47 48 Build the malicious payload with the **same package name** as the managed app and a **much larger `versionCode`** so PackageManager/Finsky treats it as a newer release:<sup>[[1]](#references)</sup> 49 50 ```text 51 android { 52 namespace = "com.workday.workdroidapp" 53 defaultConfig { 54 applicationId = "com.workday.workdroidapp" 55 versionCode = 900000004 56 versionName = "9000000004.0" 57 } 58 } 59 ``` 60 61 When Android Studio deploys:<sup>[[1]](#references)</sup> 62 63 1. **Personal user (0)** installs the malicious package normally. 64 2. **Work Profile user (1)** receives the APK in a temporary staging area and tries to treat it as an update. 65 3. CVE-2023-21257's logic sees the user is restricted → **install is denied**, but the legitimate managed app is marked uninstalled and the staged APK remains cached. 66 67 ## Intune/Finsky auto-install bypass 68 69 Within ~1–10 minutes (policy refresh interval):<sup>[[1]](#references)</sup> 70 71 1. Intune/Company Portal detects the *required* package is missing from the Work Profile. 72 2. The Work-Profile **Finsky** instance is asked to reinstall it. 73 3. During version resolution Finsky compares: 74 * Play Store metadata for `com.workday.workdroidapp`. 75 * The locally staged APK from the previous install attempt. 76 4. Because the local build has the **highest `versionCode`**, Finsky trusts it as the most recent release and installs it into the restricted Work Profile **without re-applying `DISALLOW_INSTALL_APPS` / `DISALLOW_DEBUGGING_FEATURES` checks**. 77 78 The malicious binary now resides inside the Work Profile under the genuine package name and is considered compliant by the MDM.<sup>[[1]](#references)</sup> 79 80 ## Post-exploitation opportunities 81 82 * **Work-profile data access** – other enterprise apps keep trusting Intents/content providers bound to the replaced package, enabling internal data theft and covert exfiltration from the Work Profile to attacker infrastructure.<sup>[[1]](#references)</sup> 83 * **Per-app VPN hijack** – if the replaced package is mapped to an Intune per-app VPN (MS Tunnels + Defender), the malicious build automatically inherits the VPN profile, giving direct access to internal hosts from an attacker-controlled process. 84 * **Persistence** – because the MDM now believes the required app is installed, it will **reinstall the malicious build** whenever the user or defender removes it, providing long-term foothold on BYOD Work Profiles. 85 86 ## References 87 88 - [1] [Bypassing CVE-2023-21257 via Intune Required-App Auto-Install](https://jgnr.ch/sites/android_enterprise.html)