{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T01:23:43Z","timestamp":1777339423046,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,26]],"date-time":"2023-11-26T00:00:00Z","timestamp":1700956800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Shanghai Pilot Program for Basic Research - FuDan University 21TQ1400100","award":["21TQ012"],"award-info":[{"award-number":["21TQ012"]}]},{"DOI":"10.13039\/501100013105","name":"Shanghai Rising-Star Program","doi-asserted-by":"publisher","award":["21QA1400700"],"award-info":[{"award-number":["21QA1400700"]}],"id":[{"id":"10.13039\/501100013105","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172104, 62172105, 61972099, 62102093, 62102091"],"award-info":[{"award-number":["62172104, 62172105, 61972099, 62102093, 62102091"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key Research and Development Program","award":["2021YFB3101200"],"award-info":[{"award-number":["2021YFB3101200"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,26]]},"DOI":"10.1145\/3605762.3624430","type":"proceedings-article","created":{"date-parts":[[2023,11,23]],"date-time":"2023-11-23T04:01:12Z","timestamp":1700712072000},"page":"51-57","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["TrustedDomain Compromise Attack in App-in-app Ecosystems"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-7324-6090","authenticated-orcid":false,"given":"Zhibo","family":"Zhang","sequence":"first","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-2188-0398","authenticated-orcid":false,"given":"Zhangyue","family":"Zhang","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-9026-8995","authenticated-orcid":false,"given":"Keke","family":"Lian","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7066-0109","authenticated-orcid":false,"given":"Guangliang","family":"Yang","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9298-2536","authenticated-orcid":false,"given":"Lei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0726-9996","authenticated-orcid":false,"given":"Yuan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9714-5545","authenticated-orcid":false,"given":"Min","family":"Yang","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,26]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"AQUATONE - A Tool for Domain Flyovers. Retrieved","year":"2023","unstructured":"2019. AQUATONE - A Tool for Domain Flyovers. Retrieved July 20, 2023 from https:\/\/github.com\/michenriksen\/aquatone#installation 2019. AQUATONE - A Tool for Domain Flyovers. Retrieved July 20, 2023 from https:\/\/github.com\/michenriksen\/aquatone#installation"},{"key":"e_1_3_2_1_2_1","volume-title":"Retrieved","year":"2023","unstructured":"2021. OWASP Top 10 - 2021 . Retrieved July 20, 2023 from https:\/\/owasp.org\/ Top10\/ 2021. OWASP Top 10 - 2021. Retrieved July 20, 2023 from https:\/\/owasp.org\/ Top10\/"},{"key":"e_1_3_2_1_3_1","volume-title":"Content Security Policy (CSP). Retrieved","year":"2023","unstructured":"2023. Content Security Policy (CSP). Retrieved August 9, 2023 from https:\/\/ developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/CSP 2023. Content Security Policy (CSP). Retrieved August 9, 2023 from https:\/\/ developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/CSP"},{"key":"e_1_3_2_1_4_1","unstructured":"2023. OneForAll. Retrieved July 20 2023 from https:\/\/github.com\/shmilylty\/ OneForAll  2023. OneForAll. Retrieved July 20 2023 from https:\/\/github.com\/shmilylty\/ OneForAll"},{"key":"e_1_3_2_1_5_1","unstructured":"2023. WebView. Retrieved August 9 2023 from https:\/\/developer.android.com\/ reference\/android\/webkit\/WebView  2023. WebView. Retrieved August 9 2023 from https:\/\/developer.android.com\/ reference\/android\/webkit\/WebView"},{"key":"e_1_3_2_1_6_1","volume-title":"whois | Kali Linux Tools. Retrieved","year":"2023","unstructured":"2023. whois | Kali Linux Tools. Retrieved July 20, 2023 from https:\/\/www.kali. org\/tools\/whois\/ 2023. whois | Kali Linux Tools. Retrieved July 20, 2023 from https:\/\/www.kali. org\/tools\/whois\/"},{"key":"e_1_3_2_1_7_1","volume-title":"xray. Retrieved","year":"2023","unstructured":"2023. xray. Retrieved July 20, 2023 from https:\/\/github.com\/chaitin\/xray 2023. xray. Retrieved July 20, 2023 from https:\/\/github.com\/chaitin\/xray"},{"key":"e_1_3_2_1_8_1","volume-title":"The value of WeChat as a source of information on the COVID-19 in China. Preprint]","author":"Chen Xin","year":"2020","unstructured":"Xin Chen , Xi Zhou , Huan Li , Jinlan Li , and Hua Jiang . 2020. The value of WeChat as a source of information on the COVID-19 in China. Preprint] . Bull World Health Organ 30 ( 2020 ). Xin Chen, Xi Zhou, Huan Li, Jinlan Li, and Hua Jiang. 2020. The value of WeChat as a source of information on the COVID-19 in China. Preprint]. Bull World Health Organ 30 (2020)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-05940-8_26"},{"key":"e_1_3_2_1_10_1","volume-title":"2023 ACM SIGSAC Conference on Computer and Communications Security (CCS '23)","author":"Xiaojing Liao Guoyi Ye Pei Chen","year":"2023","unstructured":"Pei Chen Xiaojing Liao Guoyi Ye Geng Hong , Mengying Wu and Min Yang . 2023 . Understanding and Detecting Abused Image Hosting Modules as Malicious Services . In 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS '23) . ACM. Pei Chen Xiaojing Liao Guoyi Ye Geng Hong, Mengying Wu and Min Yang. 2023. Understanding and Detecting Abused Image Hosting Modules as Malicious Services. In 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS '23). ACM."},{"key":"e_1_3_2_1_11_1","series-title":"Journal of Physics: Conference Series","volume-title":"Analysis of the development of WeChat mini program","author":"Hao Lei","year":"2040","unstructured":"Lei Hao , Fucheng Wan , Ning Ma , and Yicheng Wang . 2018. Analysis of the development of WeChat mini program . In Journal of Physics: Conference Series , Vol. 1087 . IOP Publishing , 06 2040 . Lei Hao, Fucheng Wan, Ning Ma, and Yicheng Wang. 2018. Analysis of the development of WeChat mini program. In Journal of Physics: Conference Series, Vol. 1087. IOP Publishing, 062040."},{"key":"e_1_3_2_1_12_1","volume-title":"WebViewOriented Testing for Android Applications. arXiv preprint arXiv:2306.03845","author":"Hu Jiajun","year":"2023","unstructured":"Jiajun Hu , Lili Wei , Yepang Liu , and Shing-Chi Cheung . 2023. ??Test : WebViewOriented Testing for Android Applications. arXiv preprint arXiv:2306.03845 ( 2023 ). Jiajun Hu, Lili Wei, Yepang Liu, and Shing-Chi Cheung. 2023. ??Test: WebViewOriented Testing for Android Applications. arXiv preprint arXiv:2306.03845 (2023)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660275"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Zihao Jin Shuo Chen Yang Chen Haixin Duan Jianjun Chen and Jianping Wu. 2023. A Security Study about Electron Applications and a Programming Methodology to Tame DOM Functionalities.. In NDSS.  Zihao Jin Shuo Chen Yang Chen Haixin Duan Jianjun Chen and Jianping Wu. 2023. A Security Study about Electron Applications and a Programming Methodology to Tame DOM Functionalities.. In NDSS.","DOI":"10.14722\/ndss.2023.24305"},{"key":"e_1_3_2_1_15_1","volume-title":"MiniTracker: Large-Scale Sensitive Information Tracking in Mini Apps","author":"Li Wei","year":"2023","unstructured":"Wei Li , Borui Yang , Hangyu Ye , Liyao Xiang , Qingxiao Tao , Xinbing Wang , and Chenghu Zhou . 2023. MiniTracker: Large-Scale Sensitive Information Tracking in Mini Apps . IEEE Transactions on Dependable and Secure Computing ( 2023 ). Wei Li, Borui Yang, Hangyu Ye, Liyao Xiang, Qingxiao Tao, Xinbing Wang, and Chenghu Zhou. 2023. MiniTracker: Large-Scale Sensitive Information Tracking in Mini Apps. IEEE Transactions on Dependable and Secure Computing (2023)."},{"key":"e_1_3_2_1_16_1","first-page":"54","article-title":"Construction of teaching model based on WeChat Mini-Program","volume":"16","author":"Liang Qinzhen","year":"2019","unstructured":"Qinzhen Liang and Chengyang Chang . 2019 . Construction of teaching model based on WeChat Mini-Program . International Journal of Science 16 , 1 (2019), 54 -- 59 . Qinzhen Liang and Chengyang Chang. 2019. Construction of teaching model based on WeChat Mini-Program. International Journal of Science 16, 1 (2019), 54--59.","journal-title":"International Journal of Science"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3421842"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417255"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1108\/APJML-08-2020-0621"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22655-7_4"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1772690.1772784"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ejon.2019.101707"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1108\/ITP-06-2020-0415"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00086"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.apnr.2017.09.008"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978363"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559340"},{"key":"e_1_3_2_1_28_1","volume-title":"SoK: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in OS-alike Apps. arXiv preprint arXiv:2306.07495","author":"Yang Yuqing","year":"2023","unstructured":"Yuqing Yang , Chao Wang , Yue Zhang , and Zhiqiang Lin . 2023. SoK: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in OS-alike Apps. arXiv preprint arXiv:2306.07495 ( 2023 ). Yuqing Yang, Chao Wang, Yue Zhang, and Zhiqiang Lin. 2023. SoK: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in OS-alike Apps. arXiv preprint arXiv:2306.07495 (2023)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560597"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1526709.1526838"},{"key":"e_1_3_2_1_31_1","volume-title":"A Small Leak Will Sink Many Ships: Vulnerabilities Related to mini-programs Permissions. In 2023 IEEE 47th Annual Computers, Software, and Applications Conference (COMPSAC)","author":"Zhang Jianyi","unstructured":"Jianyi Zhang , Leixin Yang , Yuyang Han , Zixiao Xiang , and Xiali Hei . 2023. A Small Leak Will Sink Many Ships: Vulnerabilities Related to mini-programs Permissions. In 2023 IEEE 47th Annual Computers, Software, and Applications Conference (COMPSAC) . IEEE , 595--606. Jianyi Zhang, Leixin Yang, Yuyang Han, Zixiao Xiang, and Xiali Hei. 2023. A Small Leak Will Sink Many Ships: Vulnerabilities Related to mini-programs Permissions. In 2023 IEEE 47th Annual Computers, Software, and Applications Conference (COMPSAC). IEEE, 595--606."},{"key":"e_1_3_2_1_32_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Zhang Lei","year":"2022","unstructured":"Lei Zhang , Zhibo Zhang , Ancong Liu , Yinzhi Cao , Xiaohan Zhang , Yanjun Chen , Yuan Zhang , Guangliang Yang , and Min Yang . 2022 . Identity confusion in {WebView-based} mobile app-in-app ecosystems . In 31st USENIX Security Symposium (USENIX Security 22) . 1597--1613. Lei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao, Xiaohan Zhang, Yanjun Chen, Yuan Zhang, Guangliang Yang, and Min Yang. 2022. Identity confusion in {WebView-based} mobile app-in-app ecosystems. In 31st USENIX Security Symposium (USENIX Security 22). 1597--1613."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3460081","article-title":"A measurement study of wechat mini-apps","volume":"5","author":"Zhang Yue","year":"2021","unstructured":"Yue Zhang , Bayan Turkistani , Allen Yuqing Yang , Chaoshun Zuo , and Zhiqiang Lin . 2021 . A measurement study of wechat mini-apps . Proceedings of the ACM on Measurement and Analysis of Computing Systems 5 , 2 (2021), 1 -- 25 . Yue Zhang, Bayan Turkistani, Allen Yuqing Yang, Chaoshun Zuo, and Zhiqiang Lin. 2021. A measurement study of wechat mini-apps. Proceedings of the ACM on Measurement and Analysis of Computing Systems 5, 2 (2021), 1--25.","journal-title":"Proceedings of the ACM on Measurement and Analysis of Computing Systems"},{"key":"e_1_3_2_1_34_1","volume-title":"Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-Programs. arXiv preprint arXiv:2306.08151","author":"Zhang Yue","year":"2023","unstructured":"Yue Zhang , Yuqing Yang , and Zhiqiang Lin . 2023. Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-Programs. arXiv preprint arXiv:2306.08151 ( 2023 ). Yue Zhang, Yuqing Yang, and Zhiqiang Lin. 2023. Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-Programs. arXiv preprint arXiv:2306.08151 (2023)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"crossref","unstructured":"Kaina Zhou Wen Wang Wenqian Zhao Lulu Li Mengyue Zhang Pingli Guo Can Zhou Minjie Li Jinghua An Jin Li etal 2020. Benefits of a WeChat-based multimodal nursing program on early rehabilitation in postoperative women with breast cancer: a clinical randomized controlled trial. International journal of nursing studies 106 (2020) 103565  Kaina Zhou Wen Wang Wenqian Zhao Lulu Li Mengyue Zhang Pingli Guo Can Zhou Minjie Li Jinghua An Jin Li et al. 2020. Benefits of a WeChat-based multimodal nursing program on early rehabilitation in postoperative women with breast cancer: a clinical randomized controlled trial. International journal of nursing studies 106 (2020) 103565","DOI":"10.1016\/j.ijnurstu.2020.103565"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM Workshop on Secure and Trustworthy Superapps"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3605762.3624430","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3605762.3624430","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:11Z","timestamp":1750178771000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3605762.3624430"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,26]]},"references-count":35,"alternative-id":["10.1145\/3605762.3624430","10.1145\/3605762"],"URL":"https:\/\/doi.org\/10.1145\/3605762.3624430","relation":{},"subject":[],"published":{"date-parts":[[2023,11,26]]},"assertion":[{"value":"2023-11-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}