iHunter: Hunting Privacy Violations at Scale in the Software Supply Chain on iOS
Dexin Liu, Yue Xiao, Chaoqi Zhang, Kaitao Xie, Xiaolong Bai, Shikun Zhang, Luyi Xing
摘要
Privacy violations and compliance issues in mobile apps are serious concerns for users, developers, and regulators. With many off-the-shelf tools on Android, prior works extensively studied various privacy issues for Android apps. Privacy risks and compliance issues can be equally expected in iOS apps, but have been little studied. In particular, a prominent recent privacy concern was due to diverse third-party libraries widely integrated into mobile apps whose privacy practices are non-transparent. Such a critical supply chain problem, however, was never systematically studied for iOS apps, at least partially due to the lack of the necessary tools. This paper presents the first large-scale study, based on our new taint analysis system named iHunter, to analyze privacy violations in the iOS software supply chain. iHunter performs static taint analysis on iOS SDKs to extract taint traces representing privacy data collection and leakage practices. It is characterized by an innovative iOS-oriented symbolic execution that tackles dynamic features of Objective-C and Swift and an NLP-powered generator for taint sources and taint rules. iHunter identified non-compliance in 2,585 SDKs (accounting for 40.4%) out of 6,401 iOS SDKs, signifying a substantial presence of SDKs that fail to adhere to compliance standards. We further found a high proportion (47.2% in 32,478) of popular iOS apps using these SDKs, with practical non-compliance risks violating Apple policies and major privacy laws. These results shed light on the pervasiveness and severity of privacy violations in iOS apps' supply chain. iHunter is thoroughly evaluated for its high effectiveness and efficiency. We are responsibly reporting the results to relevant stakeholders.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- PriAgent: A Collaborative Multi-Agent Framework for Auditing Android Privacy ComplianceZiwei Zhang, Zhao Li, Zhuojun Jiang, Jiangyi Yin 等AAAI 2026
- AVP-Inspect: Coordinated Cyber-Physical Testing for Privacy Analysis of COTS Apple Vision Pro ApplicationsYichang Xiong, Vamsi Shankar Simhadri, Yue Xiao, Xiaokuan ZhangCCS 2026
它引用的顶会 Paper19
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub 等USENIX Security 2018 · 被引用 400 次
- FLEXDROID: Enforcing In-App Privilege Separation in AndroidJaebaek Seo, Daehyeok Kim, Donghyun Cho, Insik Shin 等NDSS 2016 · 被引用 114 次
- Following Devil's Footprints: Cross-Platform Analysis of Potentially Harmful Libraries on Android and iOSKai Chen, Xueqiang Wang, Yi Chen, Peng Wang 等S&P 2016 · 被引用 111 次
- What Mobile Ads Know About Mobile UsersSooel Son, Daehyeok Kim, Vitaly ShmatikovNDSS 2016 · 被引用 101 次
相关 Paper
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu 等ICSE 2021 · 被引用 85 次
- iOS, Your OS, Everybody's OS: Vetting and Analyzing Network Services of iOS ApplicationsZhushou Tang, Ke Tang, Minhui Xue, Yuan Tian 等USENIX Security 2020
- Navigating Developers' Quagmire: LLM-Enabled Privacy Compliance Analysis for SDK IntegrationsZhaojie Hu, Xueqiang WangS&P 2026
- Algebraic-datatype taint tracking, with applications to understanding Android identifier leaksSydur Rahaman, Iulian Neamtiu, Xin YinFSE 2021 · 被引用 3 次
- Don't Do That! Hunting Down Visual Design Smells in Complex UIs against Design GuidelinesBo Yang, Zhenchang Xing, Xin Xia, Chunyang Chen 等ICSE 2021 · 被引用 47 次
