Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIs
Zhiao Wei, Chao Wang, Haseeb-Ur-Rehman Faheem, Luyi Xing, Yousra Aafer, Zhiqiang Lin
摘要
Mini-programs embedded within super-apps like WeChat have surged in popularity due to their flexibility and convenience, offering rich functionalities through underlying APIs. However, this tight integration introduces serious security risks: mini-programs often inherit the mobile operating system's permissions granted to their host super-app, potentially bypassing critical security checks. In this paper, we address the urgent need for more fine-grained access control tailored to mini-programs. We propose PERMSCOPE, a systematic framework to detect and analyze missing scope checks in mini-program APIs, revealing instances where Android permissions are implicitly inherited and exercised in mini-program APIs, i.e., cases where "ask and check'' primitives are absent. Our empirical analysis of four major super-apps reveals that 183 (8.85%) APIs are not properly protected at the mini-program API layer. We discuss the challenges underlying this issue and advocate for super-app developers to enforce fine-grained access control mechanisms at the API boundary, thereby strengthening the trustworthiness of the mobile super-app ecosystem.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper21
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On 等USENIX Security 2019 · 被引用 196 次
- On Demystifying the Android Application Framework: Re-Visiting Android Permission Specification AnalysisMichael Backes, Sven Bugiel, Erik Derr, Patrick D. McDaniel 等USENIX Security 2016 · 被引用 161 次
- SoK: Lessons Learned from Android Security Research for Appified Software PlatformsYasemin Acar, Michael Backes, Sven Bugiel, Sascha Fahl 等S&P 2016 · 被引用 101 次
- AceDroid: Normalizing Diverse Android Access Control Checks for Inconsistency DetectionYousra Aafer, Jianjun Huang, Yi Sun, Xiangyu Zhang 等NDSS 2018 · 被引用 95 次
- Precise Android API Protection Mapping Derivation and ReasoningYousra Aafer, Guanhong Tao, Jianjun Huang, Xiangyu Zhang 等CCS 2018 · 被引用 51 次
相关 Paper
- Uncovering API-Scope Misalignment in the App-in-App EcosystemJiarui Che, Chenkai Guo, Naipeng Dong, Jiaqi Pei 等ISSTA 2025
- Uncovering and Exploiting Hidden APIs in Mobile Super AppsChao Wang, Yue Zhang, Zhiqiang LinCCS 2023 · 被引用 11 次
- MiniChecker: Detecting Data Privacy Risk of Abusive Permission Request Behavior in Mini-ProgramsYin Wang, Ming Fan, Hao Zhou, Haijun Wang 等ASE 2024 · 被引用 2 次
- Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic AnalysisZidong Zhang, Zhentao Xie, Lingyun Ying, Qinsheng Hou 等CCS 2026
- Taintmini: Detecting Flow of Sensitive Data in Mini-Programs with Static Taint AnalysisChao Wang, Ronny Ko, Yue Zhang, Yuqing Yang 等ICSE 2023 · 被引用 36 次
