Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Android work-profile provisioning defensive security research

Back to Hasan Al Hussein's engineering portfolio

Android Work Profile Security Research

Controlled lab research on Android work-profile provisioning behavior, policy timing, and enterprise isolation boundaries.

This repository documents academic security research performed in a controlled environment. It is not intended for unauthorized access, deployment, or use against third-party devices or organizations.


Overview

This project investigates CVE-2025-22442, an Android DevicePolicyManagerService race condition that can allow unauthorized applications to be installed in a newly created work profile. The official record classifies the issue as local elevation of privilege affecting Android 13–15.

The controlled lab work focuses on the transitional period during work-profile initialization and observes when managed-profile policy enforcement becomes active.

The goal was to understand the provisioning sequence, document the risk, and translate the findings into defensive guidance for enterprise Android deployments.

At a Glance

Area Details
Topic Android enterprise work profiles
Focus Provisioning timing, managed-profile isolation, and defensive analysis
Environment Lab Android device or emulator with ADB access
Tools Python, ADB, Android Work Profile tooling
Output Research report, screenshots, and reproducible lab notes

Work Profile Environment Creation

The lab workflow monitors Android work-profile creation in real time and detects the appearance of the managed-profile user ID through ADB automation.

The provisioning process was analyzed to identify the timing window where package installation restrictions were not yet enforced.


Provisioning Analysis

The controlled research workflow includes:

  • ADB device monitoring
  • Work-profile user detection
  • Provisioning event timing analysis
  • Policy activation observation
  • Repeatable lab validation

The emphasis is on understanding the timing boundary and identifying controls that enterprise teams should validate.


Data Exposure Demonstration

The lab demonstration shows why work-profile isolation matters by modeling the kinds of enterprise-context data that could become exposed if provisioning controls fail:

  • Contact information
  • GPS location data
  • Device and network information
  • Internal work-profile files
  • Sensitive stored content

The project documents the exposure risk at a high level so defenders can reproduce validation safely in their own controlled environment.


Features

  • Android work-profile provisioning analysis
  • ADB automation
  • Timing-window investigation
  • Policy activation review
  • Enterprise-container isolation testing
  • Controlled data exposure modeling
  • Work-profile user detection
  • Real-device and emulator testing

Research Workflow

Work Profile Provisioning
        |
ADB Monitoring
        |
Managed User Detection
        |
Provisioning Timing Review
        |
Policy Activation Check
        |
Exposure Risk Documentation

Technologies Used

Security Research

  • Android Debug Bridge (ADB)
  • Python
  • Android Work Profiles
  • Provisioning analysis
  • Enterprise isolation testing

Analysis & Testing

  • Android Emulator / Physical Device
  • Automated Provisioning Monitoring
  • Enterprise Profile Testing
  • Python Automation Scripts

Results

Metric Result
Target Vulnerability CVE-2025-22442
Research Type Work-profile isolation validation
Provisioning Observation Successful
Exposure Modeling Completed in lab
Automation ADB + Python
Testing Environment Android work profile

Key Security Concepts

  • Android enterprise isolation
  • Work-profile provisioning
  • Timing-window analysis
  • Managed-profile policy activation
  • Enterprise data exposure modeling
  • Defensive validation
  • Controlled security testing

Source Code Structure

src/
├── install_loop.py
└── README.md

Future Work

  • Defensive provisioning checklist
  • MDM policy-hardening guidance
  • Broader Android version testing
  • Enterprise policy analysis
  • Safer reporting workflow for security teams

Documentation


Authors

  • Hasan Al Hussein
  • Yaman Masad
  • Omar Yousef

Khalifa University

About

Controlled defensive analysis of CVE-2025-22442 work-profile provisioning, policy timing, and enterprise isolation.

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages