Measuring Compliance Implications of Third-party Libraries' Privacy Label Disclosure Guidelines
Yue Xiao, Chaoqi Zhang, Yue Qin, Fares Fahad S. Alharbi, Luyi Xing, Xiaojing Liao
Abstract
Privacy label disclosure guideline, which specifies the data usage practices of third-party libraries (TPL), is a valuable resource for iOS app developers to accurately complete their iOS privacy labels. This is particularly important given the mandatory requirement for all apps on the App Store to disclose their data practices via privacy labels. However, it is essential to ensure the accuracy and compliance of these guidelines to ensure that accurate TPL data usage has been provided to app developers. Despite the significance of these guidelines, there is little understanding of how accurate and compliant they are in reflecting the actual data practices of third-party libraries used in iOS apps. To address this issue, our study implements a tool called Colaine to automatically check the compliance of privacy label disclosure guidelines, taking into account the configurable data practices in TPLs. Colaine analyzed 107 TPLs associated with 1,605 different configurations, shedding light on the prevalence and seriousness of privacy label disclosure guideline non-compliance issues.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 0eb4b9fb-9fee-44cf-809e-35c7dca45cbbCited by top-tier papers4
- Les Dissonances: Cross-Tool Harvesting and Polluting in Pool-of-Tools Empowered LLM AgentsZichuan Li, Jian Cui, Xiaojing Liao, Luyi XingNDSS 2026 · 24 citations
- Health Hazard, Handle with Care: Investigating the Privacy Risks of Android's Health ConnectKonstantinos Spyridakis, Ioannis Arkalakis, Michalis Diamantaris, Sotiris Ioannidis et al.USENIX Security 2026
- Bridges to Self: Silent Web-to-App Tracking on Mobile via LocalhostTim Vlummens, Aniketh Girish, Nipuna Weerasekara, Frederik Zuiderveen Borgesius et al.USENIX Security 2026
- AVP-Inspect: Coordinated Cyber-Physical Testing for Privacy Analysis of COTS Apple Vision Pro ApplicationsYichang Xiong, Vamsi Shankar Simhadri, Yue Xiao, Xiaokuan ZhangCCS 2026
Related papers
- Lalaine: Measuring and Characterizing Non-Compliance of Apple Privacy LabelsYue Xiao, Zhengyi Li, Yue Qin, Xiaolong Bai et al.USENIX Security 2023
- Demystifying Privacy Policy of Third-Party Libraries in Mobile AppsKaifa Zhao, Xian Zhan, Le Yu, Shiyao Zhou et al.ICSE 2023 · 22 citations
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 20 citations
- LibKit: Detecting Third-Party Libraries in iOS AppsDaniel Domínguez-Álvarez, Alejandro de la Cruz, Alessandra Gorla, Juan CaballeroFSE 2023 · 4 citations
- Understanding Challenges for Developers to Create Accurate Privacy Nutrition LabelsTianshi Li, Kayla Reiman, Yuvraj Agarwal, Lorrie Faith Cranor et al.CHI 2022 · 56 citations
