daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

bypass-biometric-authentication-android.md (10225B)


      1 ---
      2 title: "Bypass Biometric Authentication (Android)"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/android-app-pentesting/bypass-biometric-authentication-android.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/bypass-biometric-authentication-android.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Bypass Biometric Authentication (Android)
     14 
     15 ## **Method 1 – Bypassing with No Crypto Object Usage**
     16 
     17 The focus here is on the _onAuthenticationSucceeded_ callback, which is crucial in the authentication process. Researchers at WithSecure developed a [Frida script](https://github.com/WithSecureLABS/android-keystore-audit/blob/master/frida-scripts/fingerprint-bypass.js), enabling the bypass of the NULL _CryptoObject_ in _onAuthenticationSucceeded(...)_. The script forces an automatic bypass of the fingerprint authentication upon the method's invocation. Below is a simplified snippet demonstrating the bypass in an Android Fingerprint context, with the full application available on [GitHub](https://github.com/St3v3nsS/InsecureBanking).<sup>[[3]](#references)</sup>
     18 
     19 ```java
     20 biometricPrompt = new BiometricPrompt(this, executor, new BiometricPrompt.AuthenticationCallback() {
     21             @Override
     22             public void onAuthenticationSucceeded(@NonNull BiometricPrompt.AuthenticationResult result) {
     23                 Toast.makeText(MainActivity.this,"Success",Toast.LENGTH_LONG).show();
     24             }
     25 });
     26 ```
     27 
     28 Command to run the Frida script:
     29 
     30 ```bash
     31 frida -U -f com.generic.insecurebankingfingerprint --no-pause -l fingerprint-bypass.js
     32 ```
     33 
     34 ## **Method 2 – Exception Handling Approach**
     35 
     36 Another [Frida script](https://github.com/WithSecureLABS/android-keystore-audit/blob/master/frida-scripts/fingerprint-bypass-via-exception-handling.js) by WithSecure addresses bypassing insecure crypto object usage. The script invokes _onAuthenticationSucceeded_ with a _CryptoObject_ that hasn't been authorized by a fingerprint. If the application tries to use a different cipher object, it will trigger an exception. The script prepares to invoke _onAuthenticationSucceeded_ and handle the _javax.crypto.IllegalBlockSizeException_ in the _Cipher_ class, ensuring subsequent objects used by the application are encrypted with the new key.<sup>[[3]](#references)</sup>
     37 
     38 Command to run the Frida script:
     39 
     40 ```bash
     41 frida -U -f com.generic.insecurebankingfingerprint --no-pause -l fingerprint-bypass-via-exception-handling.js
     42 ```
     43 
     44 Upon reaching the fingerprint screen and the initiation of `authenticate()`, type `bypass()` in the Frida console to activate the bypass:
     45 
     46 ```text
     47 Spawning com.generic.insecurebankingfingerprint...
     48 [Android Emulator 5554::com.generic.insecurebankingfingerprint]-> Hooking BiometricPrompt.authenticate()...
     49 Hooking BiometricPrompt.authenticate2()...
     50 Hooking FingerprintManager.authenticate()...
     51 [Android Emulator 5554::com.generic.insecurebankingfingerprint]-> bypass()
     52 ```
     53 
     54 ## **Method 3 – Instrumentation Frameworks**
     55 
     56 Instrumentation frameworks like Xposed or Frida can be used to hook into application methods at runtime. For fingerprint authentication, these frameworks can:
     57 
     58 1. **Mock the Authentication Callbacks**: By hooking into the `onAuthenticationSucceeded`, `onAuthenticationFailed`, or `onAuthenticationError` methods of the `BiometricPrompt.AuthenticationCallback`, you can control the outcome of the fingerprint authentication process.
     59 2. **Inspect adjacent network controls**: SSL-pinning bypass is not itself a biometric bypass, but traffic instrumentation may reveal whether the backend treats the local callback as sufficient authorization or independently authorizes the sensitive action.
     60 
     61 Example command for Frida:
     62 
     63 ```bash
     64 frida -U -l script-to-bypass-authentication.js --no-pause -f com.generic.in
     65 ```
     66 
     67 ## **Method 4 – Reverse Engineering & Code Modification**
     68 
     69 Reverse engineering tools like `APKTool`, `dex2jar`, and `JD-GUI` can be used to decompile an Android application, read its source code, and understand its authentication mechanism. The steps generally include:
     70 
     71 1. **Decompiling the APK**: Convert the APK file to a more human-readable format (like Java code).
     72 2. **Analyzing the Code**: Look for the implementation of fingerprint authentication and identify potential weaknesses (like fallback mechanisms or improper validation checks).
     73 3. **Recompiling the APK**: After modifying the code to bypass fingerprint authentication, the application is recompiled, signed, and installed on the device for testing.
     74 
     75 ## **Method 5 – Using Custom Authentication Tools**
     76 
     77 There are specialized tools and scripts designed to test and bypass authentication mechanisms. For instance:
     78 
     79 1. **MAGISK Modules**: MAGISK is a tool for Android that allows users to root their devices and add modules that can modify or spoof hardware-level information, including fingerprints.
     80 2. **Custom-built Scripts**: Scripts can be written to interact with the Android Debug Bridge (ADB) or directly with the application's backend to simulate or bypass fingerprint authentication.
     81 
     82 ---
     83 
     84 ## **Method 6 – Universal Frida Hook for `BiometricPrompt` (API 28-34)**
     85 
     86 In 2023 a community Frida script branded **Universal-Android-Biometric-Bypass** appeared on CodeShare. The script hooks every overload of `BiometricPrompt.authenticate()` as well as legacy `FingerprintManager.authenticate()` and directly triggers `onAuthenticationSucceeded()` with a **fabricated `AuthenticationResult` containing a null `CryptoObject`**. Because it adapts dynamically to API levels, it still works on Android 14 (API 34) if the target app performs **no cryptographic checks on the returned `CryptoObject`**.<sup>[[1]](#references)</sup>
     87 
     88 ```bash
     89 # Install the script from CodeShare and run it against the target package
     90 frida -U -f com.target.app --no-pause -l universal-android-biometric-bypass.js
     91 ```
     92 
     93 Key ideas
     94 * The hook runs in the app's user-space process and needs no kernel exploit. On a typical production device, injecting Frida still requires a rooted/debuggable environment or an app repackaged with Frida Gadget; "user space" does not mean the test works on every unmodified, non-rooted device.
     95 * The attack remains fully silent to the UI: the system biometric dialog never appears.
     96 * Mitigation: **always verify `result.cryptoObject` and its cipher/signature before unlocking sensitive features**.
     97 
     98 ## **Method 7 – Downgrade / Fallback Manipulation**
     99 
    100 Starting with Android 11, developers can specify which authenticators are acceptable via `setAllowedAuthenticators()` (or the older `setDeviceCredentialAllowed()`). A **runtime hooking** attack can force the `allowedAuthenticators` bit-field to the weaker
    101 `BIOMETRIC_WEAK | DEVICE_CREDENTIAL` value:
    102 
    103 ```javascript
    104 // Frida one-liner – replace strong-only policy with weak/device-credential
    105 var PromptInfoBuilder = Java.use('androidx.biometric.BiometricPrompt$PromptInfo$Builder');
    106 PromptInfoBuilder.setAllowedAuthenticators.implementation = function(flags){
    107     return this.setAllowedAuthenticators(0x00FF | 0x8000); // BIOMETRIC_WEAK | DEVICE_CREDENTIAL
    108 };
    109 ```
    110 
    111 If the app does **not** cryptographically bind the result to the sensitive operation, the modified prompt may expose the device-credential fallback or accept a weak biometric. This only helps an attacker who can satisfy that fallback or enroll a biometric using the required device credentials.
    112 
    113 ## **Method 8 – Vendor / Kernel-level CVEs**
    114 
    115 Keep an eye on Android and vendor security bulletins for framework, fingerprint-sensor (FPS), HAL, and kernel flaws. Do not infer a lock-screen or in-app biometric bypass from an EoP classification alone; confirm the affected component, prerequisites, and impact in the vendor advisory.
    116 
    117 * **CVE-2023-20995** appears in the March 2023 bulletin as a moderate Android 13 System EoP. The bulletin does not attribute it to `CustomizedSensor.cpp`, Pixel 8, or a biometric unlock bypass, so those claims should not be assumed.<sup>[[4]](#references)</sup>
    118 * **CVE-2024-53835 / CVE-2024-53840** are listed as high-severity EoP issues in the Pixel fingerprint-sensor (`FPS`) component and were addressed at the December 2024 Pixel patch level. Their public bulletin entries do not disclose enough detail to claim a universal biometric bypass.<sup>[[2]](#references)</sup>
    119 
    120 Although these vulnerabilities target the lock-screen, a rooted tester may chain them with app-level flaws to bypass in-app biometrics as well.
    121 
    122 ---
    123 
    124 ### Hardening Checklist for Developers (Quick Pentester Notes)
    125 
    126 * Enforce `setUserAuthenticationRequired(true)` and appropriate `setUserAuthenticationParameters(...)` values when generating **Keystore** keys. Use `setInvalidatedByBiometricEnrollment(true)` where enrollment changes should invalidate biometric-only keys.<sup>[[5]](#references)</sup>
    127 * Reject a `CryptoObject` with **null or unexpected cipher / signature**; treat this as a fatal authentication error.
    128 * When using `BiometricPrompt`, prefer `BIOMETRIC_STRONG` and **never fall back to `BIOMETRIC_WEAK` or `DEVICE_CREDENTIAL`** for high-risk actions.
    129 * Keep `androidx.biometric` maintained, but do not rely on a library upgrade to validate application policy. The app must pass an auth-per-use `CryptoObject`, use the resulting authorized cipher/signature/MAC for the protected data, and enforce authorization again on the backend where applicable.<sup>[[5]](#references)</sup>
    130 
    131 ## References
    132 
    133 - [1] [Universal Android Biometric Bypass – Frida CodeShare](https://codeshare.frida.re/@ax/universal-android-biometric-bypass/)
    134 - [2] [Android Pixel Security Bulletin 2024-12-01](https://source.android.com/security/bulletin/pixel/2024-12-01)
    135 - [3] [How Secure is your Android Keystore Authentication?](https://labs.reversec.com/posts/2019/08/how-secure-is-your-android-keystore-authentication)
    136 - [4] [Pixel Update Bulletin—March 2023](https://source.android.com/docs/security/bulletin/pixel/2023-03-01)
    137 - [5] [Android Developers - Show a biometric authentication dialog](https://developer.android.com/identity/sign-in/biometric-auth)