❗️🔹🔹🔹🔹🔹🔹🔹🔹🔹🔹🔹🔹
Graphene-OS allows IPC inter-process communication and Binders between multiple applications on the device. This can leak data and bypass disabled internet permission of the app.
Scenario: I use Google’s Keyboard (with internet disabled). However, I’ve Gmail with internet access enabled (of course). If Google wished, then can send a custom update to both apps on my device and take the keystrokes from Gboard and relay via Gmail.
Graphene OS should allow user to fully isolate an app within a given profile.
Similarly, I can install Facebbok (with personal profile) and Instagram (with hidden identity) on same device, same profile and still Meta will have no idea (other than probably correlation of IP and other meta data).
Solution: Add a switch in app permissions (for each app) to toggle on / off IPC for an app. And additionally limit which apps it can be allowed for IPC.
