The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps
Yizhe Shi, Zhemin Yang, Kangwei Zhong, Guangliang Yang, Yifan Yang, Xiaohan Zhang, Min Yang
摘要
—In recent years, the app-in-app paradigm, involving super-app and mini-app, has been becoming increasingly popular in the mobile ecosystem. Super-app platforms offer mini-app servers access to a suite of powerful and sensitive services, including payment processing and mini-app analytics. This access empowers mini-app servers to enhance their offerings with robust and practical functionalities and better serve their mini-apps. To safeguard these essential services, a credential-based authentication system has been implemented, facilitating secure access between super-app platforms and mini-app servers. However, the design and workflow of the crucial credential mechanism still remain unclear. More importantly, its security has not been comprehensively understood or explored to date. In this paper, we conduct the first systematic study of the credential system in the app-in-app paradigm and draw the security landscape of credential leakage risks. Consequently, our study shows that 21 popular super-app platforms delegate sensitive services to mini-app servers with seven types of credentials. Unfortunately, these credentials may suffer from leakage threats caused by malicious mini-app users, posing serious security threats to both super-app platforms and mini-app servers. Then, we design and implement a novel credential security verification tool, called KeyMagnet, that can effectively assess the security implications of credential leakage. To tackle unstructured and dynamically retrieved credentials in the app-in-app paradigm, KeyMagnet extracts and understands the semantics of
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic AnalysisZidong Zhang, Zhentao Xie, Lingyun Ying, Qinsheng Hou 等CCS 2026
- Real or Rogue? Detecting Malicious Miniapps with Deceptive Reporting InterfaceYuqing Yang, Zhiqiang LinWWW 2026
- GUI0: Self-Evolving Foundational GUI Agents in Super App EcosystemsXinyi Wang, Wei Dai, Kyle Qiao, Ke Wang 等ACL 2026
- Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud ServicesYizhe Shi, Zhemin Yang, Dingyi Liu, Kangwei Zhong 等NDSS 2026
- When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-gamesPei Chen, Geng Hong, Yicheng Qin, Huazhe Wang 等USENIX Security 2026
它引用的顶会 Paper22
- Reinforcement learning based curiosity-driven testing of Android applicationsMinxue Pan, An Huang, Guoxin Wang, Tian Zhang 等ISSTA 2020 · 被引用 166 次
- Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing WebpagesYun Lin, Ruofan Liu, Dinil Mon Divakaran, Jun Yang Ng 等USENIX Security 2021 · 被引用 164 次
- How Bad Can It Git? Characterizing Secret Leakage in Public GitHub RepositoriesMichael Meli, Matthew R. McNiece, Bradley ReavesNDSS 2019 · 被引用 130 次
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 被引用 123 次
- JAW: Studying Client-side CSRF with Hybrid Property Graphs and Declarative TraversalsSoheil Khodayari, Giancarlo PellegrinoUSENIX Security 2021 · 被引用 51 次
相关 Paper
- Uncovering API-Scope Misalignment in the App-in-App EcosystemJiarui Che, Chenkai Guo, Naipeng Dong, Jiaqi Pei 等ISSTA 2025
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang 等CCS 2020 · 被引用 48 次
- Understanding Miniapp Malware: Identification, Dissection, and CharacterizationYuqing Yang, Yue Zhang, Zhiqiang LinNDSS 2025
- I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-appsYifeng Cai, Ziqi Zhang, Mengyu Yao, Junlin Liu 等USENIX Security 2025
- Identity Confusion in WebView-based Mobile App-in-app EcosystemsLei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao 等USENIX Security 2022
