Taintmini: Detecting Flow of Sensitive Data in Mini-Programs with Static Taint Analysis
Chao Wang, Ronny Ko, Yue Zhang, Yuqing Yang, Zhiqiang Lin
Abstract
Mini-programs, which are programs running inside mobile super apps such as WeChat, often have access to privacy-sensitive information, such as location data and phone numbers, through APUs provided by the super apps. This access poses a risk of privacy sensitive data leaks, either accidentally from carelessly programmed mini-programs or intentionally from malicious ones. To address this concern, it is crucial to track the flow of sensitive data in mini-programs for either human analysis or automated tools. Although existing taint analysis techniques have been widely studied, they face unique challenges in tracking sensitive data flows in mini-programs, such as cross-language, cross-page, and cross-mini-program data flows. This paper presents a novel framework, Taintmini, which addresses these challenges by using a novel universal data flow graph approach that captures data flows within and across mini-programs. We have evaluated Taintminiwith 238,866 mini-programs and detect 27,184 that contain sensitive data flows. We have also applied Taintminito detect privacy leakage colluding mini-programs and identify 455 such programs from them that clearly violate privacy policy.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get e0563528-c34a-4a9d-92f3-cd244f0503ffCited by top-tier papers15
- RIoTFuzzer: Companion App Assisted Remote Fuzzing for Detecting Vulnerabilities in IoT DevicesKaizheng Liu, Ming Yang, Zhen Ling, Yue Zhang et al.CCS 2024 · 8 citations
- Wemint:Tainting Sensitive Data Leaks in WeChat Mini-ProgramsShi Meng, Liu Wang, Shenao Wang, Kailong Wang et al.ASE 2023 · 8 citations
- MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-ProgramsZidong Zhang, Qinsheng Hou, Lingyun Ying, Wenrui Diao et al.CCS 2024 · 6 citations
- Is It Safe to Share Your Files? An Empirical Security Analysis of Google WorkspaceLiuhuo Wan, Kailong Wang, Haoyu Wang, Guangdong BaiWWW 2024 · 6 citations
- Attention! Your Copied Data is Under Monitoring: A Systematic Study of Clipboard Usage in Android AppsYongliang Chen, Ruoqin Tang, Chaoshun Zuo, Xiaokuan Zhang et al.ICSE 2024 · 5 citations
Related papers
- Demystifying Cookie Sharing Risks in WebView-based Mobile App-in-app EcosystemsMiao Zhang, Shenao Wang, Guilin Zheng, Yanjie Zhao et al.ASE 2025 · 1 citation
- Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-ProgramsYue Zhang, Yuqing Yang, Zhiqiang LinCCS 2023 · 14 citations
- Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic AnalysisZidong Zhang, Zhentao Xie, Lingyun Ying, Qinsheng Hou et al.CCS 2026
- One Size Does Not Fit All: Uncovering and Exploiting Cross Platform Discrepant APIs in WeChatChao Wang, Yue Zhang, Zhiqiang LinUSENIX Security 2023
- MiniChecker: Detecting Data Privacy Risk of Abusive Permission Request Behavior in Mini-ProgramsYin Wang, Ming Fan, Hao Zhou, Haijun Wang et al.ASE 2024 · 2 citations
