Skip to content

[LeakScope] 2 Android lifecycle/memory violations detected #5

Description

LeakScope: Android Lifecycle & Memory Leak Violations

About this report: This issue was automatically generated by LeakScope, a static analysis tool for Android lifecycle violations and memory leaks built on the Soot framework. This is part of an ongoing academic research study targeting ICSE 2027. No immediate action is required — we would greatly appreciate your feedback on whether these findings are accurate.

Summary

LeakScope detected 2 potential issue(s) across 2 detector type(s):

Severity Count
🔴 High 1
🟡 Medium 0
🟢 Low (improvement opportunity) 1
Detector Count Severity Description
ThreadedUIReference 1 🔴 High Worker thread captures Activity/Fragment/View reference
ViewBindingOpportunity 1 🟢 Low Manual findViewById() calls — ViewBinding migration opportunity

Detailed Findings

🔴 ThreadedUIReference

Worker thread captures Activity/Fragment/View reference

Finding #1MainActivity\n// (Full source code omitted for brevity)\n"

{
  "text_input": "package com.nemesis.droidcrypt;\n\n// Class: com.nemesis.droidcrypt.MainActivity\n// (Full source code omitted for brevity)\n",
  "output": "Yes",
  "project": "droidcrypt",
  "explanation": "Scenario 1: Worker thread holds UI object reference\nClass: com.nemesis.droidcrypt.MainActivity\nMethod: void processFile(boolean)\nStatement: $r6 \u003d new java.lang.Thread\nCaptured UI objects:\n  - r0 : com.nemesis.droidcrypt.MainActivity\nRisk: UI object will be kept in memory until thread completes\nFix: Use WeakReference or avoid passing UI objects to worker threads\n"
}
{
  "text_input": "package com.nemesis.droidcrypt;\n\n// Class: com.nemesis.droidcrypt.MainActivity\n// (Full source code omitted for brevity)\n",
  "output": "Yes",
  "project": "droidcrypt",
  "explanation": "Scenario 1: Worker thread holds UI object reference\nClass: com.nemesis.droidcrypt.MainActivity\nMethod: void processFile(boolean)\nStatement: $r1 \u003d new com.nemesis.droidcrypt.MainActivity$$Ex
… (truncated for brevity)

🟢 ViewBindingOpportunity

Manual findViewById() calls — ViewBinding migration opportunity

Finding #2MainActivity

View Binding Migration Opportunity
Class: com.nemesis.droidcrypt.MainActivity
Type: Activity
Current Pattern: Manual view lookup
findViewById() Calls:
  • findViewById in onCreate
  • findViewById in onCreate
  • findViewById in onCreate
  • findViewById in onCreate
  • findViewById in onCreate
Benefits of View Binding:
- Eliminates boilerplate findViewById() calls
- Compile-time type safety for view references
- Reduced null pointer exceptions
- Cleaner, more maintainable code
Note: This is a code modernization suggestion, not a memory leak

How to respond to this issue:

  • If a finding is a true positive: consider applying the recommended fix and closing this issue.
  • If a finding is a false positive: please leave a comment explaining why — your feedback directly improves our research.
  • If you have questions: reply here or open a discussion.

This report was generated by LeakScope as part of the ICSE 2027 research artifact. Tool analyzes compiled APKs using Soot static analysis on DroidCrypt.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions