Privacy Kit 1.23.1
Privacy Kit 1.23.1
A coherence/leak-fix release from a full 63-identifier code audit, plus the browser hardening and the profile-hub Scripts entry.
Identifier leak-path fixes (secondary read paths that leaked the real value)
- Carrier strings — the biggest:
getSimOperator()etc. were spoofed butgsm.operator.*/gsm.sim.operator.*props leaked the real carrier. Now covered on the Java getter,getprop, and native layers at once. - Time zone —
persist.sys.timezoneprop + ICUTimeZone.getDefault(). - Locale —
LocaleList.getDefault/getAdjustedDefault+Configuration.getLocales()(the paths most apps read). - Hostname —
net.hostnameprop. - GSF ID — 6-arg + Bundle
query()overloads. - Install time —
Os.stat/lstatst_mtime/st_ctimeon the app's own paths. - ADB / Developer-options — legacy
Settings.Secure.getIntpath. - Wi-Fi MAC/BSSID now lowercase (matches real Android); Bluetooth uppercase — closes a case-mismatch tell.
- Restriction alt-paths closed (
getAccountsByTypeForPackage,getCellLocation).
Browser fingerprint armor
- Canvas
toDataURLnow actually diverges (was a no-op), WebRTC public-IP (STUN srflx) leak blocked, User-Agent Client Hints + JS timezone/locale pinned to the profile.
Scripts
- In-process Lua script hooks with a dedicated editor + an ad-block template; a Scripts entry now sits in each profile's hub.
KPM (
privacykit_kpm.kpm, KernelPatch 0.13.5) remains experimental/APatch-only and unverified on-device — can brick boot; recoverable devices only, off by default.
SHA-256
PrivacyKit-1.23.1.apk 699B327E8576344A315C5B15FFA0E80C3C0B39C7FB89F23FAB3EAA6D45FCA094
PKProbe-1.23.1.apk E55E49DC2D6C2053B5D2CA5532BC465E807A65A4F48F4E7185A2A4AA5C9C1E40
privacykit_kpm.kpm C9D4EB74CD04D73C2AEEE8BA23B9A5D2976286C040889658E5157BFBBD52AE67
Signing: 95:E9 cert — installs over an existing Privacy Kit.