logo

Intercepting traffic on Android with Mainline and Conscrypt

ID: b32f1201-90f6-598d-b49c-c30ee887bfab

STIX ID: report--b32f1201-90f6-598d-b49c-c30ee887bfab

Feed Name: NVISO Labs

Date Published: 2025-06-05

Date Updated: 2026-04-28

Author: Jeroen Beckers

...
...

The report explains how Android’s move to Mainline/Conscrypt-managed root CAs affects TLS interception and details updates to the AlwaysTrustUserCerts Magisk module to restore interception from Android 7 through Android 16 Beta. It covers copying user certificates to the system store, rbind-mounting into the Conscrypt APEX across zygote and child processes, handling Google Play System Updates and SDK gating (A14+), addressing Android 15+ mount propagation with rbind, and ensuring resilience by reinjecting mounts after zygote restarts while preserving CA disablement behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.