WRITEUP · MOBILE · TLS · 2026 · @YNSMROZTAS

Conscrypt owns the CA list

● live clk --:--:-- module · traffic

Mainline ships Conscrypt on its own clock. The process does not load the store you think you patched.

tls // storeobserve
radar--:--:--
AndroScope Conscrypt Mainline lab only

01 — Two clocks on the same phone

A modern image advertises two patch dates. One is the Android Security Update. The other is a Google Play System Update that refreshes Mainline modules without an OTA. Conscrypt — the default Java TLS provider since Android 9, BoringSSL underneath — lives in that second stream. The CA list can move while the rest of the build number stays still.

ASU Android Security Update system image · slow clock GPSU Play System Update Mainline APEX · Conscrypt

02 — Two stores, one winner

Classic intercept assumed one bag of roots: /system/etc/security/cacerts, plus a user store the app opted into. From Android 14 the Conscrypt APEX ships its own cacerts. If that folder is present, it wins. A user cert sitting only in the old path is invisible to the TrustManager the process actually constructed.

user CA settings · user store /system/.../cacerts image roots apex conscrypt wins if present process TrustManager loads the APEX list first. private /apex mount per app. sibling processes do not share your edit.

03 — Why the lab session looks empty

You installed a user CA. Network Security Config on a lab build even allows user CAs. The handshake still dies. AndroScope traffic + defense modules on an authorized lab process answer the only question that matters: which provider, which store path, which NSC flag. They do not publish a mount kit.

C  TRAFFIC & SECRETS
35  Request intelligence           ★
E  DEFENSE
50  TLS pinning observer           ★

session — lab.sample.app
[tls] provider: Conscrypt
[tls] store class: APEX cacerts present
[tls] user CA: installed, not in the loaded list
[tls] NSC user-ca flag: on — still not the APEX bag
[nsc] cleartext: off · domain pin: none

mitsec@lab.sample.app:

04 — Walk the class on the lab build

1 · Attach

Authorized lab variant. Traffic module + TLS observer. No second Play app. No other UID.

2 · Name the provider

Print the default SSLContext provider. Conscrypt means the APEX path is in play on current images.

3 · Name the store

Does the process see an APEX cacerts bag? If yes, that list is the one the handshake uses. The user store is a spectator.

4 · Read NSC

networkSecurityConfig can allow user CAs and still lose to the APEX list. Record both facts. Do not collapse them.

5 · Watch one request

Trigger login or a sync. Request intelligence logs the failure class: pin, unknown CA, or expired. Empty log means you did not hit TLS yet.

6 · Stop

The public note ends at store identity. Overlay, rbind, zygote remount, and module names stay off this page.

05 — Older images, same idea

Mainline back-ported an updatable CA bag onto 11–13 via Play System Updates. The Java side still fell back to /system below 14 in several builds. Treat “I copied a cert into /system” as incomplete evidence. Ask the process. AndroScope prints what that process loaded, not what the host overlay claims.

06 — What this is not

AndroScope reports provider + store class + NSC. It does not ship the remount recipe on this site.

Fix, on the app side

YUNUS EMRE ÖZTAŞ · MITSEC · LAB BUILD ONLY