Identity Confusion in WebView-based Mobile App-in-app Ecosystems
Lei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao, Xiaohan Zhang, Yanjun Chen, Yuan Zhang, Guangliang Yang, Min Yang
摘要
Mobile applications (apps) often delegate their own functions to other parties, which makes them become a super ecosystem hosting these parties. Therefore, such mobile apps are being called super-apps, and the delegated parties are subsequently called sub-apps, behaving like "app-in-app". Sub-apps not only load (third-party) resources like a normal app, but also have access to the privileged APIs provided by the super-app. This leads to an important research question-determining who can access these privileged APIs. Real-world super-apps, according to our study, adopt three types of identities-namely web domains, sub-app IDs, and capabilities-to determine privileged API access. However, existing identity checks of these three types are often not well designed, leading to a disobey of the least privilege principle. That is, the granted recipient of a privileged API is broader than intended, thus defined as an "identity confusion" in this paper. To the best of our knowledge, no prior works have studied this type of identity confusion vulnerability. In this paper, we perform the first systematic study of identity confusion in real-world app-in-app ecosystems. We find that confusions of the aforementioned three types of identities are widespread among all 47 studied super-apps. More importantly, such confusions lead to severe consequences such as manipulating users' financial accounts and installing malware on a smartphone. We responsibly reported all of our findings to developers of affected super-apps, and helped them to fix their vulnerabilities.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper19
- Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-ProgramsYue Zhang, Yuqing Yang, Zhiqiang LinCCS 2023 · 被引用 14 次
- Uncovering and Exploiting Hidden APIs in Mobile Super AppsChao Wang, Yue Zhang, Zhiqiang LinCCS 2023 · 被引用 11 次
- ωTest: WebView-Oriented Testing for Android ApplicationsJiajun Hu, Lili Wei, Yepang Liu, Shing-Chi CheungISSTA 2023 · 被引用 8 次
- Wemint:Tainting Sensitive Data Leaks in WeChat Mini-ProgramsShi Meng, Liu Wang, Shenao Wang, Kailong Wang 等ASE 2023 · 被引用 8 次
- Tabbed Out: Subverting the Android Custom Tab Security ModelPhilipp Beer, Marco Squarcina, Lorenzo Veronese, Martina LindorferS&P 2024 · 被引用 7 次
它引用的顶会 Paper15
- What Mobile Ads Know About Mobile UsersSooel Son, Daehyeok Kim, Vitaly ShmatikovNDSS 2016 · 被引用 101 次
- SoK: Lessons Learned from Android Security Research for Appified Software PlatformsYasemin Acar, Michael Backes, Sven Bugiel, Sascha Fahl 等S&P 2016 · 被引用 101 次
- Automated Generation of Event-Oriented Exploits in Android Hybrid AppsGuangliang Yang, Jeff Huang, Guofei GuNDSS 2018 · 被引用 79 次
- Detecting Node.js prototype pollution vulnerabilities via object lookup analysisSong Li, Mingqing Kang, Jianwei Hou, Yinzhi CaoFSE 2021 · 被引用 49 次
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang 等CCS 2020 · 被引用 48 次
相关 Paper
- Uncovering API-Scope Misalignment in the App-in-App EcosystemJiarui Che, Chenkai Guo, Naipeng Dong, Jiaqi Pei 等ISSTA 2025
- Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud ServicesYizhe Shi, Zhemin Yang, Dingyi Liu, Kangwei Zhong 等NDSS 2026
- I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-appsYifeng Cai, Ziqi Zhang, Mengyu Yao, Junlin Liu 等USENIX Security 2025
- Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability DetectionYuqing Yang, Yue Zhang, Zhiqiang LinCCS 2022 · 被引用 29 次
- An Empirical Study of Web Resource Manipulation in Real-world Mobile ApplicationsXiaohan Zhang, Yuan Zhang, Qianqian Mo, Hao Xia 等USENIX Security 2018 · 被引用 15 次
