In the last few years, the Android platform has gone through a lot of changes and security enhancements. Most of these improvements relate to low-level mechanisms and current devices are significantly more difficult to compromise than ever before. However, without a "trusted UI", many of these mechanisms can be bypassed. This talk will provide an overview of two of the biggest UI-related open problems in Android security: clickjacking and phishing. In particular, it will feature UI clickjacking attacks against a wide range of sensitive apps, and how modern features of Android, such as mobile password managers and Instant Apps, can be used to mount the stealthiest phishing attacks known to date. This talk will also discuss why it is so difficult to eradicate these problems and what we can do to defend ourselves.