RootFree Attacks: Exploiting Mobile Platform's Super Apps From Desktop

Chao Wang, Yue Zhang, Zhiqiang Lin · 2024

In recent years, there has been a surge in the popularity of mobile super apps, which consolidate a variety of services, including messaging, ride-hailing, and e-commerce, into a single application, eliminating the need to switch between different apps. Originally tailored for mobile usage, super apps like WeChat and WeCom have expanded their reach to desktop platforms, including Windows. However, different operating systems have different threat models (e.g., Windows can directly grant users with root privilege but Android and iOS do not). Therefore, the single super app (including both its host app and miniapps) can face completely different threats in different platforms. In this paper, we systematically study the attacks caused by the discrepancies from different platforms. Specifically, we show that there are at least two classes of attacks, dubbed RootFree attacks, against mobile super apps: layer below that attacks the super apps from privileged software, and layer up that attacks the super apps from the internal malicious miniapps. We have disclosed our attacks and the corresponding vulnerabilities to the host app vendor, and received bug bounties. These vulnerabilities all are ranked as high severity vulnerabilities, and some of them have already been patched.

Read the paper · More papers on PaperTik