Hazard Integrated: Understanding Security Risks in App Extensions to Team Chat Systems
Mingming Zha, Jice Wang, Yuhong Nan, Xiaofeng Wang, Yuqing Zhang, Zelin Yang
Abstract
—Team Chat ( TACT ) systems are now widely used for online collaborations and project management. A unique feature of these systems is their integration of third-party apps, which extends their capabilities but also brings in the complexity that could potentially put the TACT system and its end-users at risk. In this paper, for the first time, we demonstrate that third-party apps in TACT systems indeed open the door to new security risks, such as privilege escalation, deception, and privacy leakage. We studied 12 popular TACT systems, following the key steps of a third-party app’s life cycle (its installation, update, configuration, and runtime operations). Notably, we designed and implemented a pipeline for efficiently identifying the security risks of TA APIs, a core feature provided for system-app communication. Our study leads to the discovery of 55 security issues across the 12 platforms, with 25 in the install and configuration stages and 30 vulnerable (or risky) APIs. These security weaknesses are mostly introduced by improper design, lack of fine-grained access control, and ambiguous data-access policies. We reported our findings to all related parties, and 8 have been acknowledged. Although we are still working with the TACT vendors to determine the security impacts of the remaining flaws, their significance has already been confirmed by our user study, which further reveals users’ concerns about some security policies implemented on mainstream TACT platforms and their misconceptions about the protection in place. Also, our communication with the vendors indicates that their threat models have not been well-thought-out, with some assumptions conflicting with each other. We
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9ff1faf8-490d-4372-9e72-e41262a8dc54Cited by top-tier papers3
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Enforcing End-to-end Security for Remote Conference ApplicationsYuelin Liu, Huangxun Chen, Zhice YangS&P 2024 · 5 citations
- Maginot Line: Assessing a New Cross-app Threat to PII-as-Factor Authentication in Chinese Mobile AppsFannv He, Yan Jia, Jiayu Zhao, Yue Fang et al.NDSS 2024
Builds on6
- Charting the Attack Surface of Trigger-Action IoT PlatformsQi Wang, Pubali Datta, Wei Yang, Si Liu et al.CCS 2019 · 162 citations
- Dangerous Skills: Understanding and Mitigating Security Risks of Voice-Controlled Third-Party Functions on Virtual Personal Assistant SystemsNan Zhang, Xianghang Mi, Xuan Feng, XiaoFeng Wang et al.S&P 2019 · 160 citations
- Finding Clues for Your Secrets: Semantics-Driven, Learning-Based Privacy Discovery in Mobile AppsYuhong Nan, Zhemin Yang, Xiaofeng Wang, Yuan Zhang et al.NDSS 2018 · 79 citations
- A First Look at ZoombombingChen Ling, Utkucan Balci, Jeremy Blackburn, Gianluca StringhiniS&P 2021 · 51 citations
- Why Eve and Mallory Still Love Android: Revisiting TLS (In)Security in Android ApplicationsMarten Oltrogge, Nicolas Huaman, Sabrina Amft, Yasemin Acar et al.USENIX Security 2021 · 45 citations
Related papers
- Experimental Security Analysis of the App Model in Business Collaboration PlatformsYunang Chen, Yue Gao, Nick Ceccio, Rahul Chatterjee et al.USENIX Security 2022
- A First Look at Security and Privacy Risks in the RapidAPI EcosystemSong Liao, Long Cheng, Xiapu Luo, Zheng Song et al.CCS 2024 · 3 citations
- Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party ApplicationsNanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu et al.CCS 2023 · 15 citations
- Identifying privacy weaknesses from multi-party trigger-action integration platformsKulani Mahadewa, Yanjun Zhang, Guangdong Bai, Lei Bu et al.ISSTA 2021 · 25 citations
- Identity Confusion in WebView-based Mobile App-in-app EcosystemsLei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao et al.USENIX Security 2022
