UID-Based Sandbox (Android)
Definition
Android's application isolation model in which each installed app receives a unique Linux user ID at install time. The app's private data directory at /data/data/<package_name> is owned by that UID with mode 700, preventing any other app from reading it without root or OS-mediated sharing.
- Platform
- Android
- Mechanism
- Unique Linux UID per installed app
- Data path
- /data/data/<package_name>
- Permission mode
- 700 (owner-only access)
Common questions
Why does the Android UID sandbox matter for mobile forensic acquisition?+
Because each app's private data is walled off by Linux user permissions, a standard logical extraction without root access cannot read another app's private directory, which is why physical or root-level acquisition methods are needed to recover full app data on a locked-down device.
How does rooting a device defeat the UID sandbox for forensic purposes?+
Root access grants the superuser UID, which bypasses the per-app ownership restriction entirely, letting an examiner or acquisition tool read any app's private directory regardless of which UID originally owns it.
Related terms
- APFS (Apple File System)
- The default file system on iOS devices since iOS 10.3. Features include 64-bit inode numbers, copy-on-write metadata, file-level encryption using per-file keys,...
- App Sandbox (iOS)
- The iOS isolation mechanism combining UNIX file permissions, signed entitlements, and TrustedBSD mandatory access control. Each app is confined to a container...
- Data Protection Classes (iOS)
- iOS encrypts each file under one of four protection classes that control when the file's encryption key is available: Complete (key available...
- Ext4
- The fourth extended file system, the default Linux file system used for the userdata partition on most Android devices before widespread F2FS...
- F2FS (Flash-Friendly File System)
- A log-structured file system designed for NAND flash, used on the userdata partition of many modern Android devices including Samsung Galaxy and...