Pride and Prejudice in Progressive Web Apps: Abusing Native App-like Features in Web Applications
Jiyeon Lee, Hayeon Kim, Junghwan Park, Insik Shin, Sooel Son
Abstract
Progressive Web App (PWA) is a new generation of Web application designed to provide native app-like browsing experiences even when a browser is offline. PWAs make full use of new HTML5 features which include push notification, cache, and service worker to provide short-latency and rich Web browsing experiences.
We conduct the first systematic study of the security and privacy aspects unique to PWAs. We identify security flaws in main browsers as well as design flaws in popular third-party push services, that exacerbate the phishing risk. We introduce a new sidechannel attack that infers the victim's history of visited PWAs. The proposed attack exploits the offline browsing feature of PWAs using a cache. We demonstrate a cryptocurrency mining attack which abuses service workers. Defenses and recommendations to mitigate the identified security and privacy risks are suggested with in-depth understanding.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d94ed7f3-3449-4875-9b65-195e81d795a3Cited by top-tier papers8
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang et al.CCS 2020 · 48 citations
- "Shhh...be quiet!" Reducing the Unwanted Interruptions of Notification Permission Prompts on ChromeIgor Bilogrevic, Balazs Engedy, Judson L. Porter III, Nina Taft et al.USENIX Security 2021 · 10 citations
- InviCloak: An End-to-End Approach to Privacy and Performance in Web Content DistributionShihan Lin, Rui Xin, Aayush Goel, Xiaowei YangCCS 2022 · 5 citations
- Melting Pot of Origins: Compromising the Intermediary Web Services that Rehost WebsitesTakuya Watanabe, Eitaro Shioji, Mitsuaki Akiyama, Tatsuya MoriNDSS 2020
- Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy LeakageSoroush Karami, Panagiotis Ilia, Jason PolakisNDSS 2021
Builds on7
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- Beauty and the Burst: Remote Identification of Encrypted Video StreamsRoei Schuster, Vitaly Shmatikov, Eran TromerUSENIX Security 2017 · 205 citations
- PhishEye: Live Monitoring of Sandboxed Phishing KitsXiao Han, Nizar Kheir, Davide BalzarottiCCS 2016 · 118 citations
- What Mobile Ads Know About Mobile UsersSooel Son, Daehyeok Kim, Vitaly ShmatikovNDSS 2016 · 101 citations
- How the Web Tangled Itself: Uncovering the History of Client-Side Web (In)SecurityBen Stock, Martin Johns, Marius Steffens, Michael BackesUSENIX Security 2017 · 67 citations
Related papers
- Fill in the Blanks: Empirical Analysis of the Privacy Threats of Browser Form AutofillXu Lin, Panagiotis Ilia, Jason PolakisCCS 2020 · 24 citations
- SWAPP: A New Programmable Playground for Web Application SecurityPhakpoom Chinprutthiwong, Jianwei Huang, Guofei GuUSENIX Security 2022
- Robust Website Fingerprinting Through the Cache Occupancy ChannelAnatoly Shusterman, Lachlan Kang, Yarden Haskal, Yosef Meltser et al.USENIX Security 2019 · 159 citations
- Prime+Probe 1, JavaScript 0: Overcoming Browser-based Side-Channel DefensesAnatoly Shusterman, Ayush Agarwal, Sioli O'Connell, Daniel Genkin et al.USENIX Security 2021 · 73 citations
- Extension Breakdown: Security Analysis of Browsers Extension Resources Control PoliciesIskander Sánchez-Rola, Igor Santos, Davide BalzarottiUSENIX Security 2017 · 67 citations
