Logo image
RootFree Attacks: Exploiting Mobile Platform's Super Apps From Desktop
Conference proceeding

RootFree Attacks: Exploiting Mobile Platform's Super Apps From Desktop

Yue Zhang, Chao Wang and Zhiqiang Lin
ASIA CCS '24: Proceedings of the 19th ACM Asia Conference on Computer and Communications Security, pp 830-842
Jul 2024
url
https://doi.org/10.1145/3634737.3645001View
Published, Version of Record (VoR)Open Access via Drexel Libraries Read and Publish Program 2024Open Access (License Unspecified) Restricted

Abstract

Hidden APIs Superapp Security Miniapp Security Web Security App-in-App Security
In recent years, there has been a surge in the popularity of mobile super apps, which consolidate a variety of services, including messaging, ride-hailing, and e-commerce, into a single application, eliminating the need to switch between different apps. Originally tailored for mobile usage, super apps like WeChat and WeCom have expanded their reach to desktop platforms, including Windows. However, different operating systems have different threat models (e.g., Windows can directly grant users with root privilege but Android and iOS do not). Therefore, the single super app (including both its host app and miniapps) can face completely different threats in different platforms. In this paper, we systematically study the attacks caused by the discrepancies from different platforms. Specifically, we show that there are at least two classes of attacks, dubbed RootFree attacks, against mobile super apps: layer below that attacks the super apps from privileged software, and layer up that attacks the super apps from the internal malicious miniapps. We have disclosed our attacks and the corresponding vulnerabilities to the host app vendor, and received bug bounties. These vulnerabilities all are ranked as high severity vulnerabilities, and some of them have already been patched.

Metrics

32 Record Views
1 citations in Scopus

Details

InCites Highlights

Data related to this publication, from InCites Benchmarking & Analytics tool:

Collaboration types
Domestic collaboration
Web of Science research areas
Computer Science, Information Systems
Computer Science, Interdisciplinary Applications
Telecommunications
Logo image