Florian Draschbacher

Florian Draschbacher

Mobile Security Researcher · Graz, Austria

I am a mobile security researcher from Graz, Austria. In 2026, I completed my PhD in Computer Science under the supervision of Prof. Stefan Mangard at ISEC, the Institute of Information Security (former IAIK) at Graz University of Technology. My research revolves around various aspects of mobile security, such as mobile application security, mobile supply chain security, platform security, and the security of mobile connectivity.

Interests

  • Mobile Security
  • Application Analysis
  • Platform Security
  • Supply Chain Security
  • Wired & Wireless Connectivity Protocols

Education

  • PhD in Computer Science, 2026 Graz University of Technology
  • Dipl.-Ing. (MSc) in Computer Science, 2021 Graz University of Technology
  • BSc in Computer Science, 2017 Graz University of Technology

Publications

2026

File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS

CVE-2025-68788
Website

Clone2Pwn: A Systematic Security Analysis of Data Migration Tools in the Android Ecosystem

CVE-2025-15515, CVE-2025-21060, CVE-2025-21061, CVE-2025-21062, CVE-2025-21064, CVE-2025-21078, CVE-2025-27387, CVE-2025-68963

Exploring Misconfigured Security Across the Mobile Platform Stack

Shortlist, TÜV Austria Wissenschaftspreis 2026
2025

The Doom of Device Drivers: Your Android Device (Most Likely) has N-Day Kernel Vulnerabilities

ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade ago

Nomination, Best Mobile Bug, Pwnie Awards 2026 Artifacts evaluated: Available CVE-2024-20900, CVE-2024-43085, CVE-2025-24193, CVE-2024-54096
2024

Manifest Problems: Analyzing Code Transparency for Android Application Bundles

Artifacts evaluated: Available, Functional, Reproduced CVE-2023-21387
GitHub

Defects-in-Depth: Analyzing the Integration of Effective Defenses against One-Day Exploits in Android Kernels

Artifacts evaluated: Available, Functional, Reproduced
GitHub Slides
2023

A2P2: An Android Application Patching Pipeline Based On Generic Changesets

Best Paper Award
GitHub Slides

CryptoShield: Automatic On-Device Mitigation for Crypto API Misuse in Android Applications

GitHub Slides

Talks

2026
2025

ChoiceJacking via Malicious Chargers

2024
2023

Awards & CVEs

2026
2025
2024
2023