{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,30]],"date-time":"2026-01-30T04:55:56Z","timestamp":1769748956324,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":25,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,26]],"date-time":"2023-11-26T00:00:00Z","timestamp":1700956800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["328202204"],"award-info":[{"award-number":["328202204"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,26]]},"DOI":"10.1145\/3605762.3624432","type":"proceedings-article","created":{"date-parts":[[2023,11,23]],"date-time":"2023-11-23T04:01:12Z","timestamp":1700712072000},"page":"1-9","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Systematic Analysis of Security and Vulnerabilities in Miniapps"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-8552-0696","authenticated-orcid":false,"given":"Yuyang","family":"Han","sequence":"first","affiliation":[{"name":"Beijing Electronic Science and Technology Institute, BJ, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-4376-5198","authenticated-orcid":false,"given":"Xu","family":"Ji","sequence":"additional","affiliation":[{"name":"Beijing Electronic Science and Technology Institute, BJ, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1789-8414","authenticated-orcid":false,"given":"Zhiqiang","family":"Wang","sequence":"additional","affiliation":[{"name":"Beijing Electronic Science and Technology Institute, BJ, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8765-053X","authenticated-orcid":false,"given":"Jianyi","family":"Zhang","sequence":"additional","affiliation":[{"name":"Beijing Electronic Science and Technology Institute, BJ, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,26]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"The value of WeChat as a source of information on the COVID-19 in China. Preprint]","author":"Chen Xin","year":"2020","unstructured":"Xin Chen , Xi Zhou , Huan Li , Jinlan Li , and Hua Jiang . 2020. The value of WeChat as a source of information on the COVID-19 in China. Preprint] . Bull World Health Organ , Vol . 30 ( 2020 ). Xin Chen, Xi Zhou, Huan Li, Jinlan Li, and Hua Jiang. 2020. The value of WeChat as a source of information on the COVID-19 in China. Preprint]. Bull World Health Organ , Vol. 30 (2020)."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-05940-8_26"},{"key":"e_1_3_2_1_3_1","volume-title":"Proceedings of the IEEE international symposium on secure software engineering","volume":"1","author":"Halfond William G","year":"2006","unstructured":"William G Halfond , Jeremy Viegas , Alessandro Orso , 2006 . A classification of SQL-injection attacks and countermeasures . In Proceedings of the IEEE international symposium on secure software engineering , Vol. 1 . IEEE, 13--15. William G Halfond, Jeremy Viegas, Alessandro Orso, et al. 2006. A classification of SQL-injection attacks and countermeasures. In Proceedings of the IEEE international symposium on secure software engineering, Vol. 1. IEEE, 13--15."},{"key":"e_1_3_2_1_4_1","volume-title":"WASC Threat Classification v2.0 report. https:\/\/help.hcltechsw.com\/appscan\/Enterprise\/10.0.1\/topics\/r_wasc_threat_classifications_report.html Retrieved","year":"2025","unstructured":"hcltechsw.com. 2021. WASC Threat Classification v2.0 report. https:\/\/help.hcltechsw.com\/appscan\/Enterprise\/10.0.1\/topics\/r_wasc_threat_classifications_report.html Retrieved May 25, 2025 from hcltechsw.com. 2021. WASC Threat Classification v2.0 report. https:\/\/help.hcltechsw.com\/appscan\/Enterprise\/10.0.1\/topics\/r_wasc_threat_classifications_report.html Retrieved May 25, 2025 from"},{"key":"e_1_3_2_1_5_1","volume-title":"Mini Program Security Construction and Development Insights. https:\/\/www.aldzs.com\/viewpointarticle?id=16623 Retrieved","author":"Aladdin Institute","year":"2023","unstructured":"Aladdin Institute . 2023. Mini Program Security Construction and Development Insights. https:\/\/www.aldzs.com\/viewpointarticle?id=16623 Retrieved July 28, 2023 from Aladdin Institute. 2023. Mini Program Security Construction and Development Insights. https:\/\/www.aldzs.com\/viewpointarticle?id=16623 Retrieved July 28, 2023 from"},{"key":"e_1_3_2_1_6_1","first-page":"501","article-title":"A Research on the Construction of Campus Errand Running Service Platform Based on WeChat Mini App","volume":"8","author":"Jun Wu","year":"2022","unstructured":"Wu Jun , Jiajun Li , Fengning Liu , Zesen Yuan , Yu Han , and Jin Zhang . 2022 . A Research on the Construction of Campus Errand Running Service Platform Based on WeChat Mini App . World Scientific Research Journal , Vol. 8 , 9 (2022), 501 -- 507 . Wu Jun, Jiajun Li, Fengning Liu, Zesen Yuan, Yu Han, and Jin Zhang. 2022. A Research on the Construction of Campus Errand Running Service Platform Based on WeChat Mini App. World Scientific Research Journal, Vol. 8, 9 (2022), 501--507.","journal-title":"World Scientific Research Journal"},{"key":"e_1_3_2_1_7_1","volume-title":"Michelle Osborne, Steve VanDeBogart, and David Ziegler.","author":"Krohn Maxwell N","year":"2005","unstructured":"Maxwell N Krohn , Petros Efstathopoulos , Cliff Frey , M Frans Kaashoek , Eddie Kohler , David Mazieres , Robert Tappan Morris , Michelle Osborne, Steve VanDeBogart, and David Ziegler. 2005 . Make Least Privilege a Right (Not a Privilege).. In HotOS. Maxwell N Krohn, Petros Efstathopoulos, Cliff Frey, M Frans Kaashoek, Eddie Kohler, David Mazieres, Robert Tappan Morris, Michelle Osborne, Steve VanDeBogart, and David Ziegler. 2005. Make Least Privilege a Right (Not a Privilege).. In HotOS."},{"key":"e_1_3_2_1_8_1","first-page":"54","article-title":"Construction of teaching model based on WeChat Mini-Program","volume":"16","author":"Liang Qinzhen","year":"2019","unstructured":"Qinzhen Liang and Chengyang Chang . 2019 . Construction of teaching model based on WeChat Mini-Program . International Journal of Science , Vol. 16 , 1 (2019), 54 -- 59 . Qinzhen Liang and Chengyang Chang. 2019. Construction of teaching model based on WeChat Mini-Program. International Journal of Science, Vol. 16, 1 (2019), 54--59.","journal-title":"International Journal of Science"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3421842"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417255"},{"key":"e_1_3_2_1_11_1","volume-title":"https:\/\/new.qq.com\/rain\/a\/20230326A028AX00 Retrieved","author":"AZhongguancun Online. 2023. WeChat's 1.3 Billion Monthly Activities Steadily Sitting on the Throne of the First National APP.","year":"2023","unstructured":"AZhongguancun Online. 2023. WeChat's 1.3 Billion Monthly Activities Steadily Sitting on the Throne of the First National APP. https:\/\/new.qq.com\/rain\/a\/20230326A028AX00 Retrieved July 26, 2023 from AZhongguancun Online. 2023. WeChat's 1.3 Billion Monthly Activities Steadily Sitting on the Throne of the First National APP. https:\/\/new.qq.com\/rain\/a\/20230326A028AX00 Retrieved July 26, 2023 from"},{"key":"e_1_3_2_1_12_1","volume-title":"https:\/\/owasp.org\/Top10\/ Retrieved","author":"OWASP","year":"2022","unstructured":"owasp.org. 2021. OWASP Top 10 - 2021. https:\/\/owasp.org\/Top10\/ Retrieved May 25, 2022 from owasp.org. 2021. OWASP Top 10 - 2021. https:\/\/owasp.org\/Top10\/ Retrieved May 25, 2022 from"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.3390\/su142013483"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1108\/APJML-08-2020-0621"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ejon.2019.101707"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00086"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"crossref","unstructured":"Chao Wang Yue Zhang and Zhiqiang Lin. 2023 b. Uncovering and Exploiting Hidden APIs in Mobile Super Apps. arxiv: 2306.08134 [cs.CR]  Chao Wang Yue Zhang and Zhiqiang Lin. 2023 b. Uncovering and Exploiting Hidden APIs in Mobile Super Apps. arxiv: 2306.08134 [cs.CR]","DOI":"10.1145\/3576915.3616676"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.apnr.2017.09.008"},{"key":"e_1_3_2_1_19_1","volume-title":"WeChat mini programs' Safety guidelines Development Principles and Considerations. https:\/\/developers.weixin.qq.com\/miniprogram\/dev\/framework\/security.html Retrieved","year":"2023","unstructured":"Wechat. 2021. WeChat mini programs' Safety guidelines Development Principles and Considerations. https:\/\/developers.weixin.qq.com\/miniprogram\/dev\/framework\/security.html Retrieved July 22, 2023 from Wechat. 2021. WeChat mini programs' Safety guidelines Development Principles and Considerations. https:\/\/developers.weixin.qq.com\/miniprogram\/dev\/framework\/security.html Retrieved July 22, 2023 from"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560597"},{"key":"e_1_3_2_1_21_1","volume-title":"Analysis of the development status and development trend of China's small program industry","author":"Yun Xian","year":"2023","unstructured":"Xian Yun . 2023. Analysis of the development status and development trend of China's small program industry in 2023 . https:\/\/www.sgpjbg.com\/info\/4a34cfc1716174fa600c82a4662c02a4.html Retrieved July 25, 2023 from Xian Yun. 2023. Analysis of the development status and development trend of China's small program industry in 2023. https:\/\/www.sgpjbg.com\/info\/4a34cfc1716174fa600c82a4662c02a4.html Retrieved July 25, 2023 from"},{"key":"e_1_3_2_1_22_1","volume-title":"Identity Confusion in WebView-based Mobile App-in-app Ecosystems. In 31st USENIX Security Symposium (USENIX Security 22)","author":"Zhang Lei","year":"2022","unstructured":"Lei Zhang , Zhibo Zhang , Ancong Liu , Yinzhi Cao , Xiaohan Zhang , Yanjun Chen , Yuan Zhang , Guangliang Yang , and Min Yang . 2022 . Identity Confusion in WebView-based Mobile App-in-app Ecosystems. In 31st USENIX Security Symposium (USENIX Security 22) . USENIX Association, Boston, MA, 1597--1613. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/zhang-lei Lei Zhang, Zhibo Zhang, Ancong Liu, Yinzhi Cao, Xiaohan Zhang, Yanjun Chen, Yuan Zhang, Guangliang Yang, and Min Yang. 2022. Identity Confusion in WebView-based Mobile App-in-app Ecosystems. In 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Boston, MA, 1597--1613. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/zhang-lei"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3410220.3460106"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Yue Zhang Yuqing Yang and Zhiqiang Lin. 2023. Don't Leak Your Keys: Understanding Measuring and Exploiting the AppSecret Leaks in Mini-Programs. arxiv: 2306.08151 [cs.CR]  Yue Zhang Yuqing Yang and Zhiqiang Lin. 2023. Don't Leak Your Keys: Understanding Measuring and Exploiting the AppSecret Leaks in Mini-Programs. arxiv: 2306.08151 [cs.CR]","DOI":"10.1145\/3576915.3616591"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"Kaina Zhou Wen Wang Wenqian Zhao Lulu Li Mengyue Zhang Pingli Guo Can Zhou Minjie Li Jinghua An Jin Li etal 2020. Benefits of a WeChat-based multimodal nursing program on early rehabilitation in postoperative women with breast cancer: a clinical randomized controlled trial. International journal of nursing studies Vol. 106 (2020) 103565. io  Kaina Zhou Wen Wang Wenqian Zhao Lulu Li Mengyue Zhang Pingli Guo Can Zhou Minjie Li Jinghua An Jin Li et al. 2020. Benefits of a WeChat-based multimodal nursing program on early rehabilitation in postoperative women with breast cancer: a clinical randomized controlled trial. International journal of nursing studies Vol. 106 (2020) 103565. io","DOI":"10.1016\/j.ijnurstu.2020.103565"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM Workshop on Secure and Trustworthy Superapps"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3605762.3624432","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3605762.3624432","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:11Z","timestamp":1750178771000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3605762.3624432"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,26]]},"references-count":25,"alternative-id":["10.1145\/3605762.3624432","10.1145\/3605762"],"URL":"https:\/\/doi.org\/10.1145\/3605762.3624432","relation":{},"subject":[],"published":{"date-parts":[[2023,11,26]]},"assertion":[{"value":"2023-11-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}