Mitigating Injection Attacks against E2EE Applications via View-Based Partitioning

No ratings

Presented at USENIX Security 2025 by

A recent line of work has explored injection attacks against end-to-end encrypted (E2EE) applications. These involve sending adversarial content to a target victim E2EE client, thereby "injecting it" into otherwise honest client state, followed by monitoring some encrypted backup or other server-side state to violate confidentiality. These attacks exploit features such as compression before encryption of backups, and practitioners so far lack a way to prevent these attacks while retaining practicality.