Understanding and Analyzing Privacy Risks in Mobile Consent-Management Platforms
Jingzhou Ye, Fares Alharbi, Luyi Xing, Xueqiang Wang
Abstract
Today's mobile applications (apps) increasingly reuse third-party SDKs to provide essential functionalities. However, the integration of these SDKs into an app's supply chain introduces complexity, making it challenging to manage the SDKs and ensure their collective compliance with privacy regulations. Recently, consent management platforms (CMPs) have emerged, being increasingly adopted by mobile apps as a centralized mechanism and app-global configuration to help manage SDKs, particularly enabling all SDKs in an app to comply with the same user consent status for personal data processing. However, the question of whether the adoption of established CMPs ensures the validity of user consent specifically in mobile apps remains underexplored. This study addresses this gap in knowledge by conducting the first systematic investigation of the problems associated to obtaining user consent with CMP GUIs in realworld mobile apps (across Android and iOS). To achieve this, we developed a novel framework, Diulens, that efficiently and comprehensively discovers CMP GUIs using a series of LLM-aided GUI analysis techniques tailored to CMPs. The framework analyzes both CMP GUIs and actual SDK usage within the apps to identify violations of privacy-accountable design, implementation, and use of CMPs (CMP DIU risks or DIU risks in short). Our findings reveal various Diu risks, such as failures to properly and consistently disclose thirdparty SDKs, ambiguous consent effects resulting from user interactions with CMP GUIs, and instances where consent is either difficult to withdraw or coerced. Attributing the causes, we found that both app developers' use (or configuration) of CMPs and flawed CMP implementations, or their combination, could cause DIU risks. We further observed differences in the adoption of CMPs and the DIU risks across the Android and iOS platforms, likely influenced by platform-specific privacy features, such as Apple's App Tracking Transparency (ATT) framework. This study provides new insights and bridges a critical knowledge gap regarding the assurance of CMPs in obtaining valid user consent in mobile apps.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get aab13229-82b9-4871-92eb-8e39cc484b71Related papers
- Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKsYifan Zhang, Zhaojie Hu, Xueqiang Wang, Yuhui Hong et al.USENIX Security 2024 · 3 citations
- CSChecker: Revisiting GDPR and CCPA Compliance of Cookie Banners on the WebMingxue Zhang, Wei Meng, You Zhou, Kui RenICSE 2024 · 5 citations
- Freely Given Consent?: Studying Consent Notice of Third-Party Tracking and Its Violations of GDPR in Android AppsTrung Tin Nguyen, Michael Backes, Ben StockCCS 2022 · 32 citations
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger et al.CHI 2020 · 491 citations
- Navigating Cookie Consent Violations Across the GlobeBrian Tang, Duc Bui, Kang G. ShinUSENIX Security 2025
