ReuNify: A Step Towards Whole Program Analysis for React Native Android Apps
Yonghui Liu, Xiao Chen, Pei Liu, John Grundy, Chunyang Chen, Li Li
Abstract
React Native is a widely-used open-source frame-work that facilitates the development of cross-platform mobile apps. The framework enables JavaScript code to interact with native-side code, such as Objective-C/Swift for iOS and Java/Kotlin for Android, via a communication mechanism provided by React Native. However, previous research and tools have overlooked this mechanism, resulting in incomplete analysis of React Native app code. To address this limitation, we have developed REUNIFY, a prototype tool that integrates the JavaScript and native-side code of React Native apps into an intermediate language that can be processed by the Soot static analysis framework. By doing so, REUNIFY enables the generation of a comprehensive model of the app's behavior. Our evaluation indicates that, by leveraging REUNIFY, the Soot-based framework can improve its coverage of static analysis for the 1,007 most popular React Native Android apps, augmenting the number of lines of Jimple code by 70%. Additionally, we observed an average increase of 84% in new nodes reached in the callgraph for these apps, after integrating REUNIFY. When REUNIFY is used for taint flow analysis, an average of two additional privacy leaks were identified. Overall, our results demonstrate that REUNIFY significantly enhances the Soot-based framework's capability to analyze React Native Android apps.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a759a101-10bf-40d7-bca7-71f8fa828393Cited by top-tier papers1
Ask how each one uses itBuilds on7
- TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTimeMingshen Sun, Tao Wei, John C. S. LuiCCS 2016 · 188 citations
- JN-SAF: Precise and Efficient NDK/JNI-aware Inter-language Static Analysis Framework for Security Vetting of Android Applications with Native CodeFengguo Wei, Xingwei Lin, Xinming Ou, Ting Chen et al.CCS 2018 · 93 citations
- Mobile App SquattingYangyu Hu, Haoyu Wang, Ren He, Li Li et al.WWW 2020 · 44 citations
- JuCify: A Step Towards Android Code Unification for Enhanced Static AnalysisJordan Samhi, Jun Gao, Nadia Daoudi, Pierre Graux et al.ICSE 2022 · 43 citations
- Mining Android API Usage to Generate Unit Test Cases for Pinpointing Compatibility IssuesXiaoyu Sun, Xiao Chen, Yanjie Zhao, Pei Liu et al.ASE 2022 · 16 citations
Related papers
- GlassWing: A Tailored Static Analysis Approach for Flutter Android AppsXiangyu Zhang, Yucheng Su, Lingling Fan, Miaoying Cai et al.ASE 2025
- NativeSummary: Summarizing Native Binary Code for Inter-language Static Analysis of Android AppsJikai Wang, Haoyu WangISSTA 2024 · 8 citations
- ReactAppScan: Mining React Application Vulnerabilities via Component GraphZhiyong Guo, Mingqing Kang, V. N. Venkatakrishnan, Rigel Gjomemo et al.CCS 2024 · 3 citations
- Algebraic-datatype taint tracking, with applications to understanding Android identifier leaksSydur Rahaman, Iulian Neamtiu, Xin YinFSE 2021 · 3 citations
- AXA: Cross-Language Analysis through Integration of Single-Language AnalysesTobias Roth, Julius Näumann, Dominik Helm, Sven Keidel et al.ASE 2024 · 2 citations
