topic. In this paper, we report that on the Android system (and likely other OSes), a weaker
form of GUI confidentiality can be breached in the form of UI state (not the pixels) by a
background app without requiring any permissions. Our finding leads to a class of attacks
which we name UI state inference attack. The underlying problem is that popular GUI
frameworks by design can potentially reveal every UI state change through a newly …