{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T01:23:43Z","timestamp":1777339423269,"version":"3.51.4"},"reference-count":65,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2021YFB3101200"],"award-info":[{"award-number":["2021YFB3101200"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172104"],"award-info":[{"award-number":["62172104"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172105"],"award-info":[{"award-number":["62172105"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61972099"],"award-info":[{"award-number":["61972099"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102093"],"award-info":[{"award-number":["62102093"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102091"],"award-info":[{"award-number":["62102091"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tifs.2024.3390553","type":"journal-article","created":{"date-parts":[[2024,4,19]],"date-time":"2024-04-19T17:22:27Z","timestamp":1713547347000},"page":"5434-5448","source":"Crossref","is-referenced-by-count":6,"title":["The Dark Forest: Understanding Security Risks of Cross-Party Delegated Resources in Mobile App-in-App Ecosystems"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-7324-6090","authenticated-orcid":false,"given":"Zhibo","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Computer Science, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9298-2536","authenticated-orcid":false,"given":"Lei","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7066-0109","authenticated-orcid":false,"given":"Guangliang","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Computer Science, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-3966-6078","authenticated-orcid":false,"given":"Yanjun","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Computer Science, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiahao","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Computer Science, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9714-5545","authenticated-orcid":false,"given":"Min","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Computer Science, Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"WeChat Miniprograms Have More Than 450 Million DAU","year":"2021"},{"key":"ref2","volume-title":"Number of Available Applications in the Google Play Store From December 2009 to December 2020","year":"2021"},{"key":"ref3","volume-title":"Tiktok One-Click Attack","year":"2023"},{"key":"ref4","volume-title":"CNCERT\/CC Security Report","year":"2023"},{"key":"ref5","volume-title":"Android Developers","year":"2023"},{"key":"ref6","first-page":"1597","article-title":"Identity confusion in WebView-based mobile app-in-app ecosystems","volume-title":"Proc. 31st USENIX Secur. Symp. (USENIX Security)","author":"Zhang"},{"key":"ref7","volume-title":"Apple Development Documentations","year":"2021"},{"key":"ref8","volume-title":"Jadx\u2014Dex to Java Decompiler","year":"2023"},{"key":"ref9","volume-title":"Tiktok Mini-App Secure Development Guide","year":"2021"},{"key":"ref10","volume-title":"Mitmproxy\u2014An Interactive HTTPS Proxy","year":"2023"},{"key":"ref11","volume-title":"A Very Powerful Clipboard: Analysis of a Samsung In-the-Wild Exploit Chain","year":"2022"},{"key":"ref12","volume-title":"Limited Access to Android Clipboard Data","year":"2023"},{"key":"ref13","volume-title":"Man-in-the-Disk: Android Apps Exposed via External Storage","year":"2018"},{"key":"ref14","first-page":"603","article-title":"50 ways to leak your data: An exploration of apps\u2019 circumvention of the Android permissions system","volume-title":"Proc. 28th USENIX Secur. Symp. (USENIX Security)","author":"Reardon"},{"key":"ref15","volume-title":"dcloudio\/uni-app: A Cross-Platform Framework Using vue.js","year":"2023"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417255"},{"key":"ref17","volume-title":"JS-WALA","year":"2023"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616591"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23418"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3543516.3460106"},{"key":"ref21","volume-title":"Unpacking WeChat wxapkgs","year":"2023"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978322"},{"key":"ref23","first-page":"1183","article-title":"Shattered chain of trust: Understanding security risks in cross-cloud IoT access delegation","volume-title":"Proc. 29th USENIX Secur. Symp. (USENIX Security)","author":"Yuan"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1088\/1742-6596\/1087\/6\/062040"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1108\/ITP-06-2020-0415"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1016\/j.apnr.2017.09.008"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijnurstu.2020.103565"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-05940-8_26"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1108\/APJML-08-2020-0621"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/j.cmpb.2020.105710"},{"issue":"1","key":"ref31","first-page":"54","article-title":"Construction of teaching model based on WeChat mini-program","volume":"16","author":"Liang","year":"2019","journal-title":"Int. J. Sci."},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1016\/j.ejon.2019.101707"},{"key":"ref33","first-page":"1189","article-title":"Industry practice of Javascript dynamic analysis on WeChat mini-programs","volume-title":"Proc. 35th IEEE\/ACM Int. Conf. Automated Softw. Eng. (ASE)","author":"Liu"},{"key":"ref34","article-title":"wtest: WebView-oriented testing for Android applications","author":"Hu","year":"2023","journal-title":"arXiv:2306.03845"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00086"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2023.3299945"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560597"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC57700.2023.00085"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616676"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660275"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134021"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516727"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23407"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-35092-5_3"},{"key":"ref45","volume-title":"Mind the Bridge\u2014New Attack Model in Hybrid Mobile Application","year":"2021"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076781"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-37119-6_15"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-05149-9_9"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_2"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2845851"},{"key":"ref51","first-page":"1","article-title":"Security enhanced (SE) Android: Bringing flexible MAC to Android","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp. (NDSS)","author":"Smalley"},{"key":"ref52","first-page":"271","article-title":"BigMAC: Fine-grained policy analysis of Android firmware","volume-title":"Proc. 29th USENIX Security Symp. (USENIX Security)","author":"Hernandez"},{"key":"ref53","first-page":"977","article-title":"Iframes\/popups are dangerous in mobile WebView: Studying and mitigating differential context vulnerabilities","volume-title":"Proc. 28th USENIX Security Symp. (USENIX Security)","author":"Yang"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00043"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2013.6575317"},{"key":"ref56","first-page":"1","article-title":"PathCutter: Severing the self-propagation path of XSS JavaScript worms in social web networks","volume-title":"Proc. NDSS","author":"Cao"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/2414456.2414460"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11379-1_14"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/3468264.3468542"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23323"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-41284-4_16"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3052998"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2017.34"},{"key":"ref64","first-page":"2183","article-title":"Composition kills: A case study of email sender authentication","volume-title":"Proc. 29th USENIX Security Symposium (USENIX Security)","author":"Chen"},{"key":"ref65","first-page":"1079","article-title":"We still don\u2019t have secure cross-domain requests: An empirical study of CORS","volume-title":"Proc. 27th USENIX Security Symposium (USENIX Security)","author":"Chen"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/10319981\/10506090.pdf?arnumber=10506090","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,5,22]],"date-time":"2024-05-22T17:34:57Z","timestamp":1716399297000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10506090\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":65,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3390553","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}