Demystifying Cookie Sharing Risks in WebView-based Mobile App-in-app Ecosystems
Miao Zhang, Shenao Wang, Guilin Zheng, Yanjie Zhao, Haoyu Wang
Abstract
Mini-programs, an emerging mobile application paradigm within super-apps, offer a seamless and installation-free experience. However, the adoption of the web-view component has disrupted their isolation mechanisms, exposing new attack surfaces and vulnerabilities. In this paper, we introduce a novel vulnerability called Cross Mini-program Cookie Sharing (CMCS), which arises from the shared web-view environment across mini-programs. This vulnerability allows unauthorized data exchange across mini-programs by enabling one mini-program to access cookies set by another within the same web-view context, violating isolation principles. As a preliminary step, we analyzed the web-view mechanisms of four major platforms, including WeChat, AliPay, TikTok, and Baidu, and found that all of them are affected by CMCS vulnerabilities. These findings were responsibly disclosed and acknowledged with two CVEs. Furthermore, we demonstrate the collusion attack enabled by CMCS, where privileged mini-programs exfiltrate sensitive user data via cookies accessible to unprivileged mini-programs. To measure the impact of collusion attacks enabled by CMCS vulnerabilities in the wild, we developed MiCoScan, a static analysis tool that detects mini-programs affected by CMCS vulnerabilities. MiCoScan employs web-view context modeling to identify clusters of mini-programs sharing the same web-view domain and cross-webview data flow analysis to detect sensitive data transmissions to/from web-views. Using MiCoScan, we conducted a large-scale analysis of 351,483 mini-programs, identifying 45,448 clusters sharing web-view domains, 7,965 instances of privileged data transmission, and 9,877 mini-programs vulnerable to collusion attacks. Our findings highlight the widespread prevalence and significant security risks posed by CMCS vulnerabilities, underscoring the urgent need for improved isolation mechanisms in mini-program ecosystems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 84f42c64-ae99-44d0-8cb1-ecb32a5e106fBuilds on13
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang et al.CCS 2020 · 48 citations
- Taintmini: Detecting Flow of Sensitive Data in Mini-Programs with Static Taint AnalysisChao Wang, Ronny Ko, Yue Zhang, Yuqing Yang et al.ICSE 2023 · 36 citations
- Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability DetectionYuqing Yang, Yue Zhang, Zhiqiang LinCCS 2022 · 29 citations
- Characterizing and Detecting Bugs in WeChat Mini-ProgramsTao Wang, Qingxin Xu, Xiaoning Chang, Wensheng Dou et al.ICSE 2022 · 19 citations
- Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-ProgramsYue Zhang, Yuqing Yang, Zhiqiang LinCCS 2023 · 14 citations
Related papers
- MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-ProgramsZidong Zhang, Qinsheng Hou, Lingyun Ying, Wenrui Diao et al.CCS 2024 · 6 citations
- Uncovering API-Scope Misalignment in the App-in-App EcosystemJiarui Che, Chenkai Guo, Naipeng Dong, Jiaqi Pei et al.ISSTA 2025
- Uncovering and Exploiting Hidden APIs in Mobile Super AppsChao Wang, Yue Zhang, Zhiqiang LinCCS 2023 · 11 citations
- Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic AnalysisZidong Zhang, Zhentao Xie, Lingyun Ying, Qinsheng Hou et al.CCS 2026
- Wemint:Tainting Sensitive Data Leaks in WeChat Mini-ProgramsShi Meng, Liu Wang, Shenao Wang, Kailong Wang et al.ASE 2023 · 8 citations
