FINDING · DETECTION

Application packaging and software supply chains in Russia's Android ecosystem can expand the effective TLS trust boundary beyond OS-level controls, enabling MITM attacks on TLS connections for apps that bundle or inherit Russian-controlled certificate authorities. This bypasses the assumption that the OS trust store constrains which CAs can intercept encrypted traffic.

From 2026-tolley-beyond-os-trustBeyond OS Trust Stores: TLS Trust in Russia’s Android Ecosystem · Abstract · 2026 · FOCI 2026

Implications

Tags

censors
ru
techniques
middlebox-interferencedpi

Extracted by claude-sonnet-4-6 — review before relying.