Lune

S&P2025Top-tier venue

Analyzing the iOS Local Network Permission from a Technical and User Perspective

David Schmidt, Alexander Ponticello, Magdalena Steinböck, Katharina Krombholz, Martina Lindorfer

2025Year
4Top-tier citations

Abstract

In the past, malicious apps attacked routers or identified locations through local network communication. To mitigate security and privacy risks from local network access, Apple introduced a new permission with iOS 14. To be effective, the permission needs to protect against technical threats, and users must be able to make an informed permission decision. The latter is presumably hindered by the intrinsic technicality of the concept of the local network.

In this paper, we perform the first comprehensive analysis of the local network permission by studying four key aspects. We investigate the security of its implementation by systematically accessing the local network. We explore local network accesses via a large-scale dynamic analysis of 10,862 iOS and Android apps. We analyze the concepts that constitute the permission prompts, as this is all the information users get before making a decision. Based on the identified concepts, we conduct an online survey (N = 150) to comprehend users' understanding of the permission, their threat awareness, and common misconceptions.

Our work reveals two methods to bypass the permission from webviews, and that the protected local network addresses are insufficient. We show how and when apps access the local network, and how the situation differs between iOS and Android. Finally, we present the light and shadow of users' understanding of the permission. While nearly every participant is aware of at least one threat (83.11%), misconceptions are even more common (84.46%).

• We demonstrate two methods to bypass the permission and show that the protected local IP address range of the permission is insufficient.

• We analyze 10,862 cross-platform apps, out of which 152 iOS and 117 Android apps access the local network, and show differences between both platforms.

• We identify reoccurring concepts in permission prompts and present insights into the developer-specified purposes.

• We show that nearly every participant (83.11%) is aware of at least one threat but also that misconceptions are widespread, as 84.46% hold at least one.

For reproducibility and to enable future work, we publish our code to study the permission, analyze apps, extract and label permission messages, and evaluate the results at: https://github.com/SecPriv/local network.

TABLE 3: Our codebook to categorize the rationales. We assigned a code if we found one of the keywords in a rationale. The column # Apps shows the number of rationales with the code, related to the total 727 apps with rationales.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

Cited by top-tier papers4

Ask how each one uses it

Builds on16

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines