USENIX Security2026Top-tier venue
Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIs
Zhiao Wei, Chao Wang, Haseeb-Ur-Rehman Faheem, Luyi Xing, Yousra Aafer, Zhiqiang Lin
Abstract
Mini-programs embedded within super-apps like WeChat have surged in popularity due to their flexibility and convenience, offering rich functionalities through underlying APIs. However, this tight integration introduces serious security risks: mini-programs often inherit the mobile operating system's permissions granted to their host super-app, potentially bypassing critical security checks. In this paper, we address the urgent need for more fine-grained access control tailored to mini-programs. We propose PERMSCOPE, a systematic framework to detect and analyze missing scope checks in mini-program APIs, revealing instances where Android permissions are implicitly inherited and exercised in mini-program APIs, i.e., cases where "ask and check'' primitives are absent. Our empirical analysis of four major super-apps reveals that 183 (8.85%) APIs are not properly protected at the mini-program API layer. We discuss the challenges underlying this issue and advocate for super-app developers to enforce fine-grained access control mechanisms at the API boundary, thereby strengthening the trustworthiness of the mobile super-app ecosystem.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on21
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On et al.USENIX Security 2019 · 196 citations
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel et al.USENIX Security 2016 · 161 citations
- SoK: Lessons Learned from Android Security Research for Appified Software PlatformsYasemin Acar, Michael Backes, Sven Bugiel, Sascha Fahl et al.S&P 2016 · 101 citations
- AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency DetectionYousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang et al.NDSS 2018 · 95 citations
- Precise Android API Protection Mapping Derivation and ReasoningYousra Aafer, Guanhong Tao, Jianjun Huang, Xiangyu Zhang et al.CCS 2018 · 51 citations
Related papers
- Uncovering API-Scope Misalignment in the App-in-App EcosystemJiarui Che, Chenkai Guo, Naipeng Dong, Jiaqi Pei et al.ISSTA 2025
- Uncovering and Exploiting Hidden APIs in Mobile Super AppsChao Wang, Yue Zhang, Zhiqiang LinCCS 2023 · 11 citations
- MiniChecker: Detecting Data Privacy Risk of Abusive Permission Request Behavior in Mini-ProgramsYin Wang, Ming Fan, Hao Zhou, Haijun Wang et al.ASE 2024 · 2 citations
- Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic AnalysisZidong Zhang, Zhentao Xie, Lingyun Ying, Qinsheng Hou et al.CCS 2026
- Taintmini: Detecting Flow of Sensitive Data in Mini-Programs with Static Taint AnalysisChao Wang, Ronny Ko, Yue Zhang, Yuqing Yang et al.ICSE 2023 · 36 citations
