Description
SharedPreferences provides convenient storage inside an Android app. Storing sensitive values such as authentication tokens, session IDs or personal identifiers in plaintext may expose them through rooted devices, backups, debug extraction or other local compromise.
Potential impact
- Authentication token or session theft
- Exposure of personal data and internal app settings
- Account access by reusing stolen values
Remediation
- Avoid storing sensitive values on the device when possible.
- If storage is necessary, protect keys with Android Keystore and use a maintained platform cryptography API or a reviewed encrypted-storage layer.
EncryptedSharedPreferenceshas been deprecated since AndroidX Security 1.1.0; do not choose it as the default for new code. - Check that the same values are not exposed through logs, backups or debugging paths.
Examples
The after-example illustrates an existing legacy EncryptedSharedPreferences implementation. Preparation of context and a Keystore-backed masterKey is omitted. Exclude this file from Auto Backup because its key may be unavailable after restoration.
Before
java
preferences.edit().putString("auth_token", token).apply();
After
java
SharedPreferences preferences = EncryptedSharedPreferences.create(
context,
"secure_prefs",
masterKey,
EncryptedSharedPreferences.PrefKeyEncryptionScheme.AES256_SIV,
EncryptedSharedPreferences.PrefValueEncryptionScheme.AES256_GCM
);
preferences.edit().putString("auth_token", token).apply();
Explanation:
- Before: Stores a sensitive value in plaintext, where backups, rooted devices, debug extraction or vulnerable local access paths may expose it.
- After: The legacy
EncryptedSharedPreferencesimplementation encrypts keys and values. For new code, choose the supported cryptography approach described above. Encryption alone cannot protect against every compromise of the device or app process.