Exploring Privacy Leakage and Data Disclosure Violations in the MacOS Application Ecosystem
Jyotirmay Chauhan, Kostas Solomos, Mir Masood Ali, Jason Polakis
摘要
The systematic and excessive data collection practices of tech companies have rendered online privacy both a necessity and a soughtafter commodity. However, while the privacy risks of the web, mobile, and IoT ecosystems have been extensively examined, desktop environments have been largely overlooked. As desktop apps continue to be widely used, they remain a critical yet understudied dimension of user privacy. In this paper, we address this gap by presenting the first, to our knowledge, comprehensive study of the mechanisms designed to regulate and disclose data collection and sharing practices in the macOS ecosystem. We adopt an app-development-centric view, and shed light on the interactions between the various macOS mechanisms that mediate apps' data access. Driven by our findings, we develop NutriScan, an analysis framework that incorporates both static and dynamic analysis techniques to create a consolidated view of macOS apps' data practices and disclosures. We use our system to dynamically analyze 1K macOS apps, and find that 85% of them access user-data APIs without disclosing it. 49.7% also exfiltrate data to advertising entities and hosting providers, 12.5% of which do so without a corresponding disclosure. We find that desktop apps are being leveraged by online trackers to enrich user profiles and device fingerprints, thus shedding new light on the true scope of the online tracking ecosystem. Our analysis reveals how the macOS app ecosystem is comprised of disjoint mechanisms with divergent data abstractions, thus increasing complexity for developers while also facilitating undisclosed privacy-invasive practices. Accordingly, we propose a series of mitigations that aim to both streamline the data disclosure process for developers and improve Apple's app vetting process.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper18
- The Feasibility of Dynamically Granted Permissions: Aligning Mobile Privacy with User PreferencesPrimal Wijesekera, Arjun Baokar, Lynn Tsai, Joel Reardon 等S&P 2017 · 被引用 156 次
- Tracking Mobile Web Users Through Motion Sensors: Attacks and DefensesAnupam Das, Nikita Borisov, Matthew CaesarNDSS 2016 · 被引用 145 次
- Tracing Information Flows Between Ad Exchanges Using Retargeted AdsMuhammad Ahmad Bashir, Sajjad Arshad, William K. Robertson, Christo WilsonUSENIX Security 2016 · 被引用 132 次
- A Privacy Analysis of Cross-device TrackingSebastian Zimmeck, Jie S. Li, Hyungtae Kim, Steven M. Bellovin 等USENIX Security 2017 · 被引用 72 次
- Exploring User Perceptions of Discrimination in Online Targeted AdvertisingAngelisa C. Plane, Elissa M. Redmiles, Michelle L. Mazurek, Michael Carl TschantzUSENIX Security 2017 · 被引用 70 次
相关 Paper
- Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKsYifan Zhang, Zhaojie Hu, Xueqiang Wang, Yuhui Hong 等USENIX Security 2024 · 被引用 3 次
- Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical RisksRishav Chourasia, Ergute Bao, Uzair Javaid, Xiaokui XiaoS&P 2026 · 被引用 2 次
- iHunter: Hunting Privacy Violations at Scale in the Software Supply Chain on iOSDexin Liu, Yue Xiao, Chaoqi Zhang, Kaitao Xie 等USENIX Security 2024 · 被引用 6 次
- Attention! Your Copied Data is Under Monitoring: A Systematic Study of Clipboard Usage in Android AppsYongliang Chen, Ruoqin Tang, Chaoshun Zuo, Xiaokuan Zhang 等ICSE 2024 · 被引用 5 次
- Fingerprinting SDKs for Mobile Apps and Where to Find Them: Understanding the Market for Device FingerprintingMichael A. Specter, Mihai Christodorescu, Abbie Farr, Bo Ma 等CCS 2025
