Don't Trust the Super-App: A Case Study of Russia's Max

📅 2026-09-10
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文研究了超级应用程序(如俄罗斯的MAX)对用户隐私和安全的潜在威胁,通过分析其监控用户活动、操控数据等行为,呼吁移动操作系统和应用商店采取措施防止此类风险。
📝 Abstract
Super-apps, an emerging mobile architecture, host third-party mini-apps inside a single app, allowing users to access diverse services. A decade of security research on the super-app ecosystem has all assumed super-apps to be a trusted intermediary. We argue this implicit trust is difficult to justify: China's WeChat is already shown to passively track its user's activity across mini-apps at extraordinary scale; Russia's MAX's parent company is reported to be deeply entangled with the state prosecution of online speech; and Iran's Bale was reported to be functioning in the world's longest internet shutdown due to its state-backed support. In this paper, we show how malicious super-apps have undeniable capabilities to silently undermine the security and privacy of mini-apps and users without leaving any trace. Using MAX as an example, we show how it can capture mini-app UI, read and write mini-app local storage, inject arbitrary JavaScript into a mini-app's runtime, mediate mini-app network traffic, and control authentication context in ways that can enable silent user impersonation. Sadly, these capabilities manifest themselves in any super-app because of the architectural privileges granted to them by design. We argue that mobile OS and app store interventions are urgently needed to close this architectural blind spot before it is further exploited.
Problem

Research questions and friction points this paper is trying to address.

super-apps
security
privacy
mini-apps
architectural privileges
Innovation

Methods, ideas, or system contributions that make the work stand out.

super-apps
security and privacy
mini-apps
architectural privileges
silent user impersonation
🔎 Similar Papers
No similar papers found.
R
Richa Priyanka
University of Michigan
A
Aaron Ortwein
University of Michigan
J
Joel Reardon
University of Calgary
M
Michael Specter
Georgia Institute of Technology
P
Piyush Kumar Sharma
Indian Institute of Technology, Delhi
Roya Ensafi
Roya Ensafi
Associate Professor, Computer Science & Engineering, University of Michigan
SecurityNetworkingInternet MeasurementTech Policy