The Clone Strikes Back: Efficient Vulnerable Code Detection in Custom Android-based Systems Conference

Luques, E, Mazzocca, C, Tuncay, GS et al. (2026). The Clone Strikes Back: Efficient Vulnerable Code Detection in Custom Android-based Systems . 1376-1393. 10.1109/EuroSP68448.2026.00089

cited authors

  • Luques, E; Mazzocca, C; Tuncay, GS; Uluagac, S

authors

abstract

  • Open-source operating systems now power a wide range of devices, from wearables and smart appliances to vehicles. To meet specific functional, security, privacy, or hardware compatibility requirements, developers often customize these systems. However, such changes often carry a cost: downstream maintainers may overlook critical security patches or inadvertently reintroduce previously mitigated vulnerabilities when integrating new features and legacy drivers. In this study, we present a novel framework designed to efficiently detect vulnerable code in Custom Operating Systems (COSs) through a dual-layer architecture that identifies both insecure code clones and the absence of expected security-critical patches. While applicable to any COS, we evaluate our framework on Android and refer to it as AndroVET. Being one of the world's largest software platforms, Android exhibits systematic fragmentation in security fixes due to its diverse vendor variants and heterogeneous patching practices, making it an ideal use case scenario. We implemented and open-sourced our framework, and thoroughly evaluated it on 14 real-world Android-based COSs. AndroVET detected 332 vulnerability instances (corresponding to 94 unique CVEs) across 14 COSs, and a GrapheneOS case study confirmed 15 absent patches from that distribution. Experimental results show that our framework achieves higher vulnerability-detection accuracy while reducing analysis time, running on average 4 times faster than existing tools.

publication date

  • January 1, 2026

Digital Object Identifier (DOI)

start page

  • 1376

end page

  • 1393