Demystifying Cookie Sharing Risks in WebView-based Mobile App-in-app Ecosystems
Fuente:
arXiv
Saved in:
| Main Authors: | Zhang, Miao, Wang, Shenao, Zheng, Guilin, Zhao, Yanjie, Wang, Haoyu |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Demystifying and Detecting Agentic Workflow Injection Vulnerabilities in GitHub Actions
by: Wang, Shenao, et al.
Published: (2026)
by: Wang, Shenao, et al.
Published: (2026)
Seeing is (Not) Believing: Practical Phishing Attacks Targeting Social Media Sharing Cards
by: Huang, Wangchenlu, et al.
Published: (2024)
by: Huang, Wangchenlu, et al.
Published: (2024)
Beyond App Markets: Demystifying Underground Mobile App Distribution Via Telegram
by: Guo, Yanhui, et al.
Published: (2024)
by: Guo, Yanhui, et al.
Published: (2024)
SoK: Understanding Vulnerabilities in the Large Language Model Supply Chain
by: Wang, Shenao, et al.
Published: (2025)
by: Wang, Shenao, et al.
Published: (2025)
On the (In)Security of LLM App Stores
by: Hou, Xinyi, et al.
Published: (2024)
by: Hou, Xinyi, et al.
Published: (2024)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
SMCP: Secure Model Context Protocol
by: Hou, Xinyi, et al.
Published: (2026)
by: Hou, Xinyi, et al.
Published: (2026)
LLM App Squatting and Cloning
by: Xie, Yinglin, et al.
Published: (2024)
by: Xie, Yinglin, et al.
Published: (2024)
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
by: Wang, Shenao, et al.
Published: (2026)
by: Wang, Shenao, et al.
Published: (2026)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
by: Liu, Yue, et al.
Published: (2025)
by: Liu, Yue, et al.
Published: (2025)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
by: Liu, Bin, et al.
Published: (2025)
by: Liu, Bin, et al.
Published: (2025)
Demystifying Progressive Web Application Permission Systems
by: Wang, Mengxiao, et al.
Published: (2025)
by: Wang, Mengxiao, et al.
Published: (2025)
From Assistants to Adversaries: Exploring the Security Risks of Mobile LLM Agents
by: Wu, Liangxuan, et al.
Published: (2025)
by: Wu, Liangxuan, et al.
Published: (2025)
Directed Greybox Fuzzing via Large Language Model
by: Xu, Hanxiang, et al.
Published: (2025)
by: Xu, Hanxiang, et al.
Published: (2025)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
by: Zhao, Jian, et al.
Published: (2024)
by: Zhao, Jian, et al.
Published: (2024)
CanCal: Towards Real-time and Lightweight Ransomware Detection and Response in Industrial Environments
by: Wang, Shenao, et al.
Published: (2024)
by: Wang, Shenao, et al.
Published: (2024)
Towards Scalable and Interpretable Mobile App Risk Analysis via Large Language Models
by: Yang, Yu, et al.
Published: (2025)
by: Yang, Yu, et al.
Published: (2025)
Large Language Models for Cyber Security: A Systematic Literature Review
by: Xu, Hanxiang, et al.
Published: (2024)
by: Xu, Hanxiang, et al.
Published: (2024)
Evaluating and Enhancing the Vulnerability Reasoning Capabilities of Large Language Models
by: Lu, Li, et al.
Published: (2026)
by: Lu, Li, et al.
Published: (2026)
Android App Feature Extraction: A review of approaches for malware and app similarity detection
by: Torka, Simon, et al.
Published: (2024)
by: Torka, Simon, et al.
Published: (2024)
GuardianPWA: Enhancing Security Throughout the Progressive Web App Installation Lifecycle
by: Wang, Mengxiao, et al.
Published: (2025)
by: Wang, Mengxiao, et al.
Published: (2025)
Measuring and Explaining the Effects of Android App Transformations in Online Malware Detection
by: Meng, Guozhu, et al.
Published: (2025)
by: Meng, Guozhu, et al.
Published: (2025)
YASA: Scalable Multi-Language Taint Analysis on the Unified AST at Ant Group
by: Wang, Yayi, et al.
Published: (2026)
by: Wang, Yayi, et al.
Published: (2026)
Browsing without Third-Party Cookies: What Do You See?
by: Lin, Maxwell, et al.
Published: (2024)
by: Lin, Maxwell, et al.
Published: (2024)
Navigating Cookie Consent Violations Across the Globe
by: Tang, Brian, et al.
Published: (2025)
by: Tang, Brian, et al.
Published: (2025)
Understanding Mobile App Reviews to Guide Misuse Audits
by: Garg, Vaibhav, et al.
Published: (2023)
by: Garg, Vaibhav, et al.
Published: (2023)
The Illusion of Anonymity: Uncovering the Impact of User Actions on Privacy in Web3 Social Ecosystems
by: Wang, Bin, et al.
Published: (2024)
by: Wang, Bin, et al.
Published: (2024)
Cybersquatting in Web3: The Case of NFT
by: Ma, Kai, et al.
Published: (2025)
by: Ma, Kai, et al.
Published: (2025)
COOKIEGUARD: Characterizing and Isolating the First-Party Cookie Jar
by: Bahrami, Pouneh Nikkhah, et al.
Published: (2024)
by: Bahrami, Pouneh Nikkhah, et al.
Published: (2024)
Demystifying Feature Engineering in Malware Analysis of API Call Sequences
by: Qu, Tianheng, et al.
Published: (2025)
by: Qu, Tianheng, et al.
Published: (2025)
Half-Moon Cookie: Private, Similarity-Based Blocklisting with TOCTOU-Attack Resilience
by: Zhang, Xinyuan, et al.
Published: (2026)
by: Zhang, Xinyuan, et al.
Published: (2026)
MiniScope: Automated UI Exploration and Privacy Inconsistency Detection of MiniApps via Two-phase Iterative Hybrid Analysis
by: Wang, Shenao, et al.
Published: (2024)
by: Wang, Shenao, et al.
Published: (2024)
I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-apps
by: Cai, Yifeng, et al.
Published: (2025)
by: Cai, Yifeng, et al.
Published: (2025)
Towards Browser Controls to Protect Cookies from Malicious Extensions
by: Tyler, Liam, et al.
Published: (2024)
by: Tyler, Liam, et al.
Published: (2024)
Security Evaluation of Android apps in budget African Mobile Devices
by: Diallo, Alioune, et al.
Published: (2025)
by: Diallo, Alioune, et al.
Published: (2025)
VoiceWukong: Benchmarking Deepfake Voice Detection
by: Yan, Ziwei, et al.
Published: (2024)
by: Yan, Ziwei, et al.
Published: (2024)
How Agentic AI Coding Assistants Become the Attacker's Shell
by: Liu, Yue, et al.
Published: (2026)
by: Liu, Yue, et al.
Published: (2026)
Unveiling the Landscape of LLM Deployment in the Wild: An Empirical Study
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
Detecting Android Malware by Visualizing App Behaviors from Multiple Complementary Views
by: Meng, Zhaoyi, et al.
Published: (2024)
by: Meng, Zhaoyi, et al.
Published: (2024)
Similar Items
-
Demystifying and Detecting Agentic Workflow Injection Vulnerabilities in GitHub Actions
by: Wang, Shenao, et al.
Published: (2026) -
Seeing is (Not) Believing: Practical Phishing Attacks Targeting Social Media Sharing Cards
by: Huang, Wangchenlu, et al.
Published: (2024) -
Beyond App Markets: Demystifying Underground Mobile App Distribution Via Telegram
by: Guo, Yanhui, et al.
Published: (2024) -
SoK: Understanding Vulnerabilities in the Large Language Model Supply Chain
by: Wang, Shenao, et al.
Published: (2025) -
On the (In)Security of LLM App Stores
by: Hou, Xinyi, et al.
Published: (2024)