On Privacy Weaknesses and Vulnerabilities in Software Systems
Pattaraporn Sangaroonsilp, Hoa Khanh Dam, Aditya Ghose
Abstract
In this digital era, our privacy is under constant threat as our personal data and traceable online/offline activities are frequently collected, processed and transferred by many software applications. Privacy attacks are often formed by exploiting vulnerabilities found in those software applications. The Common Weakness Enumeration (CWE) and Common Vulnerabilities and Exposures (CVE) systems are currently the main sources that software engineers rely on for understanding and preventing publicly disclosed software vulnerabilities. However, our study on all 922 weaknesses in the CWE and 156,537 vulnerabilities registered in the CVE to date has found a very small coverage of privacy-related vulnerabilities in both systems, only 4.45% in CWE and 0.1% in CVE. These also cover only a small number of areas of privacy threats that have been raised in existing privacy software engineering research, privacy regulations and frameworks, and relevant reputable organisations. The actionable insights generated from our study led to the introduction of 11 new common privacy weaknesses to supplement the CWE system, making it become a source for both security and privacy vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 07e948fe-ed08-489b-a05b-454ca3fe416dBuilds on7
- Towards Security and Privacy for Multi-user Augmented Reality: Foundations with End UsersKiron Lebeck, Kimberly Ruth, Tadayoshi Kohno, Franziska RoesnerS&P 2018 · 135 citations
- Privacy Risks with Facebook's PII-Based Targeting: Auditing a Data Broker's Advertising InterfaceGiridhari Venkatadri, Athanasios Andreou, Yabing Liu, Alan Mislove et al.S&P 2018 · 110 citations
- Automatically Detecting Bystanders in Photos to Reduce Privacy RisksRakibul Hasan, David J. Crandall, Mario Fritz, Apu KapadiaS&P 2020 · 67 citations
- EmPoWeb: Empowering Web Applications with Browser ExtensionsDolière Francis SoméS&P 2019 · 60 citations
- Prepose: Privacy, Security, and Reliability for Gesture-Based ProgrammingLucas Silva Figueiredo, Benjamin Livshits, David Molnar, Margus VeanesS&P 2016 · 30 citations
Related papers
- A Grounded Theory Based Approach to Characterize Software Attack SurfacesSara Moshtari, Ahmet Okutan, Mehdi MirakhorliICSE 2022 · 7 citations
- Confusing Value with Enumeration: Studying the Use of CVEs in AcademiaMoritz Schloegel, Daniel Klischies, Simon Koch, David Klein et al.USENIX Security 2025
- Demystifying the CVE Ecosystem: Community-Perceived Impacts and ProblemsYiliang Zhao, Hengzhi Ye, Minghui Zhou, Huaimin WangICSE 2026
- Large-scale Security Measurements on the Android Firmware EcosystemQinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu et al.ICSE 2022 · 21 citations
- Messy States of Wiring: Vulnerabilities in Emerging Personal Payment SystemsJiadong Lou, Xu Yuan, Ning ZhangUSENIX Security 2021 · 4 citations
