Assessing Privacy Compliance of Android Third-Party SDKs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Meng, Mark Huasong, Yan, Chuan, Zhang, Qing, Wang, Zeyu, Wang, Kailong, Teo, Sin Gee, Bai, Guangdong, Dong, Jin Song
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911010978267136
author Meng, Mark Huasong
Yan, Chuan
Zhang, Qing
Wang, Zeyu
Wang, Kailong
Teo, Sin Gee
Bai, Guangdong
Dong, Jin Song
author_facet Meng, Mark Huasong
Yan, Chuan
Zhang, Qing
Wang, Zeyu
Wang, Kailong
Teo, Sin Gee
Bai, Guangdong
Dong, Jin Song
contents Third-party Software Development Kits (SDKs) are widely adopted in Android app development, to effortlessly accelerate development pipelines and enhance app functionality. However, this convenience raises substantial concerns about unauthorized access to users' privacy-sensitive information, which could be further abused for illegitimate purposes like user tracking or monetization. Our study offers a targeted analysis of user privacy protection among Android third-party SDKs, filling a critical gap in the Android software supply chain. It focuses on two aspects of their privacy practices, including data exfiltration and behavior-policy compliance (or privacy compliance), utilizing techniques of taint analysis and large language models. It covers 158 widely-used SDKs from two key SDK release platforms, the official one and a large alternative one. From them, we identified 338 instances of privacy data exfiltration. On the privacy compliance, our study reveals that more than 30% of the examined SDKs fail to provide a privacy policy to disclose their data handling practices. Among those that provide privacy policies, 37% of them over-collect user data, and 88% falsely claim access to sensitive data. We revisit the latest versions of the SDKs after 12 months. Our analysis demonstrates a persistent lack of improvement in these concerning trends. Based on our findings, we propose three actionable recommendations to mitigate the privacy leakage risks and enhance privacy protection for Android users. Our research not only serves as an urgent call for industry attention but also provides crucial insights for future regulatory interventions.
format Preprint
id arxiv_https___arxiv_org_abs_2409_10411
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Assessing Privacy Compliance of Android Third-Party SDKs
Meng, Mark Huasong
Yan, Chuan
Zhang, Qing
Wang, Zeyu
Wang, Kailong
Teo, Sin Gee
Bai, Guangdong
Dong, Jin Song
Cryptography and Security
Software Engineering
Third-party Software Development Kits (SDKs) are widely adopted in Android app development, to effortlessly accelerate development pipelines and enhance app functionality. However, this convenience raises substantial concerns about unauthorized access to users' privacy-sensitive information, which could be further abused for illegitimate purposes like user tracking or monetization. Our study offers a targeted analysis of user privacy protection among Android third-party SDKs, filling a critical gap in the Android software supply chain. It focuses on two aspects of their privacy practices, including data exfiltration and behavior-policy compliance (or privacy compliance), utilizing techniques of taint analysis and large language models. It covers 158 widely-used SDKs from two key SDK release platforms, the official one and a large alternative one. From them, we identified 338 instances of privacy data exfiltration. On the privacy compliance, our study reveals that more than 30% of the examined SDKs fail to provide a privacy policy to disclose their data handling practices. Among those that provide privacy policies, 37% of them over-collect user data, and 88% falsely claim access to sensitive data. We revisit the latest versions of the SDKs after 12 months. Our analysis demonstrates a persistent lack of improvement in these concerning trends. Based on our findings, we propose three actionable recommendations to mitigate the privacy leakage risks and enhance privacy protection for Android users. Our research not only serves as an urgent call for industry attention but also provides crucial insights for future regulatory interventions.
title Assessing Privacy Compliance of Android Third-Party SDKs
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2409.10411