Mini-App But Great Impact: New Ways to Compromise Mobile Apps

Black Hat Asia 2025 · Day 2 · Briefings

Overview

This talk, "Mini-App But Great Impact: New Ways to Compromise Mobile Apps," presented at Black Hat Asia by Wii and Xangu, unveils a novel attack surface within the mobile ecosystem: mini apps. Traditionally, mobile application security has focused on native apps, web pages accessed via browsers, and network-based vulnerabilities. However, the proliferation of super apps that host mini apps introduces a unique architectural paradigm with distinct security implications that have largely been overlooked. This research highlights how mini apps, despite their "mini" nature, can wield significant power, potentially compromising user data and device integrity.

Watch on YouTube

Visual summary for Mini-App But Great Impact: New Ways to Compromise Mobile Apps
Visual summary for Mini-App But Great Impact: New Ways to Compromise Mobile Apps

Key moments

  1. 0:00 Talk introduction and mini-app research overview
  2. 2:15 What are mini apps and their architecture?
  3. 4:00 Mini apps compared to web and native applications
  4. 4:40 Initial security concerns and sandbox mechanisms
  5. 6:10 File system vulnerabilities: path traversal attack
  6. 8:20 Network capabilities risks and Same Origin Policy bypass

Mini-App But Great Impact: New Ways to Compromise Mobile Apps

Speakers: Wii, Xangu, Security Researchers at a leading technology company

Conference: Black Hat Asia

YouTube: https://www.youtube.com/watch?v=J5Jn0-FsAc8

Overview

This talk, "Mini-App But Great Impact: New Ways to Compromise Mobile Apps," presented at Black Hat Asia by Wii and Xangu, unveils a novel attack surface within the mobile ecosystem: mini apps. Traditionally, mobile application security has focused on native apps, web pages accessed via browsers, and network-based vulnerabilities. However, the proliferation of super apps that host mini apps introduces a unique architectural paradigm with distinct security implications that have largely been overlooked. This research highlights how mini apps, despite their "mini" nature, can wield significant power, potentially compromising user data and device integrity.

The core of the presentation lies in demonstrating how mini apps, which leverage web technologies while interacting with native device capabilities through a super app, can be exploited. The speakers delve into specific vulnerabilities related to file system access, network communication, and the discovery and invocation of hidden APIs. They also introduce the concept of prototype chain pollution as a sophisticated technique to bypass security restrictions within this environment. The findings are critical for mobile security professionals, developers of super apps and mini apps, and anyone concerned with the evolving landscape of mobile application security, offering fresh insights into safeguarding these increasingly popular platforms.

Background

▶ Watch: Talk introduction and mini-app research overview (0:00)

The rapid adoption of mobile devices has led to the emergence of mini apps as a powerful cross-platform solution. These applications are built using web technologies (like JavaScript, HTML, and CSS) but are designed to run within a super app – a native mobile application that acts as a platform or container. Examples of super apps include popular social media, messaging, or lifestyle applications that integrate a wide array of functionalities provided by third-party mini apps. This architecture allows developers to write a single codebase that can be deployed across Android, iOS, and even PC platforms, offering unparalleled reach and ease of use.

Unlike traditional native apps (which are installed as standalone packages like APKs and leverage the operating system's full capabilities) or web apps (which rely on browser engines and web servers), mini apps occupy an intriguing middle ground. They are deployed as lightweight packages within the super app, offering a user experience that feels more integrated and responsive than a web app, without the friction of a full native app installation. The super app provides the necessary resources and an execution environment, typically powered by V8 or JavaScript Core engines, allowing mini apps to invoke native capabilities suchabilities as file operations, network access, media handling, location services, and access to user information directly from JavaScript code.

While mini apps boast advantages like lighter footprint, easier distribution, and faster updates compared to native apps, and stronger native interaction capabilities compared to web apps, these benefits introduce a new set of security challenges. The key concern revolves around how the super app manages and mediates the mini app's access to sensitive device resources and user data. Critical security mechanisms such as access control, sandboxing, storage isolation, and adherence to Same-Origin Policies (SOP) become paramount. Specifically, developers must ensure vertical permission checks (only user-authorized mini apps can use sensitive APIs) and horizontal permission checks (a mini app can only access its own data, not data from other mini apps or the super app itself). Furthermore, robust sandbox mechanisms are essential to isolate code execution, storage, and runtime environments, preventing malicious mini apps from compromising the super app or other mini apps.

Key Findings

▶ Watch: Mini apps compared to web and native applications (4:00)

The research conducted a comprehensive security assessment of mini apps, comparing their security mechanisms to those of traditional web and native applications. The focus was on identifying vulnerabilities related to file system and network capabilities, which are fundamental to mini app functionality.

File System Vulnerabilities:

The team analyzed nine different mini app platforms, identifying common file-related APIs such as readFile, writeFile, and unzip. Their security testing aimed to assess or overwrite files outside the mini app's designated storage space, targeting sensitive files like the super app's cookie files or executable components such as DEX, APK, or SO files, which could potentially lead to remote code execution (RCE).

The assessment yielded significant findings:

  • Path Traversal: Two mini app platforms were found to be vulnerable to path traversal attacks due to inadequate permission and parameter input validation.
  • Symbolic Link (Symlink) Attack: Three platforms were susceptible to symlink attacks, where an attacker could create a symbolic link pointing to a sensitive file outside the mini app's sandbox.
  • Combined Unzip and Symlink Attack: A more critical vulnerability affected five platforms, where the unzip API could be combined with a symlink attack. An attacker could craft a malicious archive containing a symlink that, when unzipped, would write data to an arbitrary location outside the mini app's intended storage, potentially overwriting critical system files or exfiltrating sensitive information.

The attack process involves an attacker creating a malicious mini app, distributing it via a QR code or a link. When a user launches this mini app, it exploits the file system vulnerabilities to escape its sandbox and gain unauthorized access to the host's file space, leading to credential leaks or even RCE.

Network Capabilities Vulnerabilities:

The research also scrutinized network-related APIs, specifically request and upload APIs, which are used for making outbound requests. A critical observation was that many mini app platforms directly reuse the host super app's underlying network capabilities, leading to severe security risks:

  • Credential Exfiltration to Third Parties: One super app was found to send user credentials directly to a third-party website when a mini app utilized its request API. This represents a direct compromise of user authentication data.
  • Same-Origin Policy (SOP) Violation: Eight mini app platforms allowed mini apps deployed by third parties to send requests to the host super app's own website while including the user's cookies. This fundamentally violates the Same-Origin Policy, a cornerstone of web security, enabling Cross-Site Request Forgery (CSRF) attacks and unauthorized access to user-specific data on the super app's server.
  • Information Leakage: Due to the nature of the request API callbacks, mini apps could fully access and process the response data via JavaScript. This not only facilitated CSRF but also allowed for the leakage of sensitive information contained in server responses.

The attack flow for network vulnerabilities typically involves a malicious mini app sending a forged request to the super app's server, leveraging the user's existing login cookies. The server, unaware of the malicious origin, responds with sensitive user data, which the mini app then intercepts and exfiltrates.

Hidden APIs and Architectural Risks:

Beyond documented APIs, the researchers uncovered a critical class of vulnerabilities stemming from hidden APIs – functionalities within the super app's native layer that are accessible to mini apps but not officially documented or intended for general use. These hidden APIs can bypass security restrictions and access capabilities beyond the super app's intended design.

  • Discovery Methods:
  • JS Core Analysis: The JS Core (or JavaScript Core) acts as the bridge between mini apps' JavaScript logic and the super app's native components. By analyzing the JS Core's source code, which is often obtainable through mini app developer tools or by debugging a mobile device, researchers could systematically identify undocumented API calls.
  • App Reversal: Reversing the super app's native code responsible for handling mini app API logic proved to be the most comprehensive method. Regardless of how a mini app API is invoked, it ultimately interacts with the native layer, making native code analysis a reliable way to uncover all hidden APIs.
  • Invocation Methods:
  • Direct Invocation: Mini app APIs are often encapsulated within a global variable (e.g., X). By enumerating all functions under this global variable, researchers found hidden APIs that could be directly invoked. For instance, a method named X.hiddenRequest was identified, which inherently included the user's login credentials in its requests, posing a significant account theft risk.
  • Privileged Variables: The applyNative method within JS Core is crucial for mini apps to call native functions. By enumerating global variables, researchers located variables equipped with applyNative capabilities (e.g., thisTestVar.native), enabling them to directly invoke hidden APIs through these privileged entry points. The researchers confirmed numerous cases where hidden APIs could be invoked this way, potentially stealing user credentials and accessing private data.

Prototype Chain Pollution for Restriction Bypass:

Even after companies implemented restrictions on hidden APIs, the researchers discovered a bypass technique: prototype chain pollution. This is a common web security issue adapted for the mobile mini app context.

  • Mechanism: Prototype pollution exploits the JavaScript object model, specifically the prototype chain, to hijack key functions by replacing their original logic. For example, by polluting the Array.prototype.includes method, an attacker can alter its behavior globally.
  • Attack Scenario: In one case, a mini app system introduced a private API blacklist to prevent the invocation of hidden APIs. When a mini app attempted to call a blacklisted API, JS Core would intercept and block it by checking if the API was present in the blacklist using the includes method. By polluting Array.prototype.includes to always return false for blacklisted API checks, the researchers successfully bypassed this restriction, allowing them to freely invoke hidden APIs despite the implemented controls. This demonstrates the sophisticated level of attack possible within the mini app environment.

Technical Deep Dive

▶ Watch: Initial security concerns and sandbox mechanisms (4:40)

The architectural foundation of mini apps, relying on a JavaScript runtime (like V8 or JavaScript Core) within a native super app, creates a unique security boundary that attackers can target. The JS Core component acts as a crucial intermediary, translating JavaScript calls from the mini app into native system calls. This design, while enabling powerful cross-platform functionality, also centralizes control points that, if compromised, can expose significant vulnerabilities.

File System Exploitation:

The file system vulnerabilities identified stem from inadequate validation of input parameters in APIs like readFile, writeFile, and unzip. A classic path traversal attack involves injecting ../ sequences into file paths to navigate outside the mini app's designated sandbox directory. For example, a malicious mini app might attempt to read /data/data/com.superapp.package/shared_prefs/superapp_cookies.xml by crafting a path like ../../../../shared_prefs/superapp_cookies.xml relative to its own storage.

The symbolic link attack is more intricate. An attacker first creates a benign-looking file within the mini app's permitted storage, but then replaces it with a symbolic link pointing to a sensitive file or directory outside the sandbox. When the super app's unzip functionality, or another file operation, is invoked on this path, it follows the symlink, allowing the mini app to read or write data to an unauthorized location. This could involve overwriting the super app's executable files (e.g., .dex or .so files on Android) with malicious code, leading to remote code execution (RCE). The successful execution of these attacks indicates a failure in robust input sanitization and privilege separation mechanisms within the super app's file management layer.

Network Communication Bypass:

The network vulnerabilities exploit the super app's trust in its hosted mini apps and its underlying network stack. When a mini app uses APIs like request or upload, the super app often transparently adds user authentication tokens, such as cookies, to the outbound requests. This convenience feature becomes a critical security flaw when a malicious mini app can direct these requests to arbitrary third-party domains. If an attacker's mini app uses the request API to send a request to attacker.com, and the super app automatically includes the user's login cookies for superapp.com in this request, the attacker gains unauthorized access to the user's session.

Furthermore, the violation of the Same-Origin Policy (SOP) is a severe design flaw. The SOP dictates that a web resource (or in this case, a mini app) should only be able to interact with resources from the same origin (domain, protocol, port). When a mini app from thirdparty.com can make authenticated requests to superapp.com with the user's cookies, it essentially bypasses the SOP. This allows for Cross-Site Request Forgery (CSRF), where the mini app can perform actions on behalf of the user on superapp.com without their consent. The full access to response data via JavaScript callbacks exacerbates this, allowing mini apps to extract sensitive information (e.g., user profiles, transaction details) returned by the super app's backend.

Hidden API Exploitation:

The discovery of hidden APIs represents a significant architectural weakness. Developers of super apps often implement internal-use-only APIs that are not exposed through official documentation but remain accessible within the mini app's execution environment.

  • JS Core Analysis: This involves examining the JavaScript code that constitutes the JS Core bridge. Developers can often access this code through debugging tools provided by mini app development kits or by attaching a debugger to the mobile device. Within this code, calls to native methods are often clearly defined, even if the native method itself is not documented. For example, a pattern like NativeModule.call('hiddenFunction', args) might reveal an undocumented native capability.
  • App Reversal: This is a more involved process of decompiling and analyzing the super app's native binaries (e.g., APK files for Android, IPA files for iOS). Tools like Ghidra or IDA Pro can be used to reverse engineer the Java/Kotlin or Objective-C/Swift code, specifically focusing on the interfaces that the JS Core uses to interact with the native layer. This can reveal the full signature and functionality of all native APIs, including those marked as private or internal.

Once a hidden API is discovered, invoking it often relies on understanding the mini app's global scope. Many mini app platforms encapsulate all callable APIs within a single global object, say X. Attackers can use reflection-like techniques (e.g., Object.keys(X), for...in loops) in JavaScript to enumerate all properties and methods of X, including undocumented ones. The applyNative method within JS Core is a direct gateway to the native layer. If an attacker can gain access to a global variable that exposes this applyNative capability, they can construct arbitrary calls to any native function, effectively bypassing any higher-level API restrictions.

Prototype Chain Pollution:

This attack leverages a fundamental aspect of JavaScript's object-oriented model: prototypes. In JavaScript, objects inherit properties and methods from their prototype. If an attacker can modify the prototype of a built-in object (like Array.prototype or Object.prototype), those modifications will affect all instances of that object type, including those used by the mini app system itself.

  • Mechanism: The core principle is to inject or overwrite properties in an object's prototype. For example, Object.prototype.someProperty = 'malicious_value'. Any object that inherits from Object.prototype (which is almost all objects in JavaScript) will then have someProperty with malicious_value if it doesn't define its own someProperty.
  • Bypass Example: The researchers demonstrated this by targeting the Array.prototype.includes method. When a mini app platform uses blacklist.includes(apiName) to check if an API is forbidden, an attacker can modify Array.prototype.includes to return false whenever apiName matches a hidden API they wish to invoke. This effectively makes the blacklist check useless, allowing the malicious mini app to call any API it desires. This technique highlights the fragility of security mechanisms that rely on standard library functions when those functions can be globally polluted.

Demo / Proof of Concept

▶ Watch: File system vulnerabilities: path traversal attack (6:10)

While the talk did not feature a live, interactive demonstration, the speakers meticulously detailed the attack processes and confirmed the existence of these vulnerabilities through their research and testing. They presented attack flows and diagrams that conceptually illustrate how a malicious mini app could exploit the identified weaknesses.

For instance, the file system attack was explained with a diagram showing a "bad mini app" creating a malicious QR code or link. Upon scanning, the mini app would launch within the super app and invoke a special API to trigger a path traversal or symlink attack. This would allow the mini app to escape its sandbox and potentially read sensitive files (like super app cookie files) or overwrite executable files (like DEX, APK, or SO files), leading to credential leaks or remote code execution. The researchers explicitly stated that "According to our assessment result, we found two apps have passer risk and permission and parameter input. Three apps are affected by symbol link link attack and combine unzip and symbolink link attack. Five apps are vulnerable." This concrete enumeration of vulnerable applications serves as a strong proof of concept for the file system exploits.

Similarly, the network attack flow depicted a "malicious mini app" sending a request to the super app's server (e.g., getUserInfo). Crucially, because the super app's request API sends these calls with user cookies, the server responds with user data. The malicious mini app then intercepts this response, gaining unauthorized access to sensitive user information. The speakers confirmed this with findings like "we identified one super app that send user credential to a third party website" and "we find eight apps requests with credentials to first party website," providing quantitative evidence of these network vulnerabilities.

The discovery and invocation of hidden APIs were also detailed with specific examples. The researchers described how they could enumerate global variables to find undocumented functions like X.hiddenRequest that inherently included user credentials, or identify privileged variables with applyNative capabilities to directly call native functions. The prototype chain pollution attack was illustrated with a "specific case" where the includes method on Array.prototype was hijacked to bypass a private API blacklist, allowing a mini app to invoke otherwise restricted hidden APIs. These detailed explanations, backed by successful identification and exploitation in their testing environments, collectively serve as compelling proof of concept for the practical feasibility and impact of these novel attack vectors.

Defensive Implications

▶ Watch: Network capabilities risks and Same Origin Policy bypass (8:20)

The findings presented in this talk highlight critical areas where super app and mini app platforms must bolster their security posture. The mitigation strategies proposed by the researchers can be broadly categorized into three core principles: sandbox isolation, permission control, and runtime security.

  1. Sandbox Isolation:

Super apps must implement robust and independent operating environments for each mini app. This involves strict process isolation and storage sandboxing. Each mini app should run in its own isolated process with minimal privileges, preventing it from interfering with other mini apps or the super app itself. For storage, each mini app's data should be strictly segregated and accessible only by that specific mini app. This prevents horizontal permission bypasses and file system attacks like path traversal and symlink exploits. Technologies like containerization or virtual environments could be considered at a micro-level to enforce this isolation more effectively. Developers should ensure that file paths provided by mini apps are rigorously sanitized to prevent ../ sequences and that symbolic links are not followed when performing file operations, especially during archive extraction (unzip).

  1. Permission Control:

Granular and strictly enforced permission control is paramount. Super apps must meticulously manage mini app access rights to sensitive resources.

  • API Access: All APIs that interact with the file system, network, location services, media, and user data must be subject to explicit user consent and strict validation. This includes both vertical permission checks (ensuring the user has authorized the specific mini app to use a sensitive API) and horizontal permission checks (ensuring the mini app only accesses its own authorized data).
  • Network Requests: The request and upload APIs need significant hardening. Super apps should enforce strict domain name verification for all outbound network requests initiated by mini apps. Requests to third-party domains should never automatically include the user's super app cookies. The Same-Origin Policy must be rigorously enforced, preventing mini apps from making authenticated requests to the super app's own domain without explicit, secure authorization mechanisms. Furthermore, the response data from network requests should be filtered and sanitized before being made fully accessible to mini app JavaScript callbacks, preventing information leakage.
  • Hidden APIs: Super app developers must conduct thorough internal security audits to identify and either remove or properly secure any hidden APIs. If hidden APIs are deemed necessary for internal functionalities, they must be made inaccessible to mini apps through strong access control mechanisms and not just a blacklist that can be bypassed. Techniques like Object.freeze() can be applied to global objects or prototypes to prevent malicious modifications and prototype chain pollution.
  1. Runtime Security:

Super apps should implement comprehensive runtime security monitoring and control over mini app execution environments. This involves managing and limiting resource consumption (memory, CPU, GPU) to prevent denial-of-service attacks or malicious code from causing system instability. Dynamic analysis and sandboxing technologies can help detect and prevent malicious behavior at runtime. Regular security updates for the super app's JS Core and native components are also crucial to patch newly discovered vulnerabilities and improve overall security posture. Furthermore, the use of Content Security Policy (CSP) and other web security headers within the mini app's webview environment can further restrict potential attack vectors, such as arbitrary script execution.

Key Takeaways

  • Mini apps represent a significant and often overlooked attack surface in the mobile ecosystem, bridging web technologies with native device capabilities through super apps.
  • Common mini app APIs related to file systems (readFile, writeFile, unzip) and network (request, upload) are vulnerable to critical exploits like path traversal, symlink attacks, Same-Origin Policy violations, and credential exfiltration.
  • Hidden APIs, undocumented functionalities within super apps accessible to mini apps, pose a severe risk, enabling unauthorized access to sensitive user data and system capabilities.
  • Sophisticated techniques like prototype chain pollution can bypass implemented security restrictions, allowing malicious mini apps to invoke blacklisted APIs and compromise the super app's integrity.
  • Effective defense requires a multi-layered approach focusing on rigorous sandbox isolation, granular permission control (including strict domain verification and enforcement of SOP), and robust runtime security monitoring and mitigation strategies.
  • Super app developers must proactively audit their platforms for hidden APIs, implement strong input validation, and secure the JavaScript execution environment to prevent prototype pollution and other advanced attacks.

About the Speaker(s)

The research presented was conducted by Wii and Xangu, alongside other contributors from their team. They are security researchers and developers at a security research and development team focused on privacy and data protection within a leading technology company. Their expertise spans mobile, web, and cloud security, and they are active bug hunters. The team has a history of sharing their cutting-edge research at prestigious security conferences globally, having previously spoken at Black Hat USA, Europe, and Asia.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research by Wii and Xangu is a critical deep dive into the often-overlooked security landscape of mobile mini apps. They didn't just find a few bugs; they identified a novel attack surface, detailing how vulnerabilities in file system access, network communication, hidden APIs, and sophisticated prototype chain pollution can lead to significant compromise within super apps. This isn't theoretical; it's a demonstration of real-world exploitation vectors impacting widely adopted platforms. Anyone involved in mobile security, from developers to CISO, needs to absorb these findings to understand and mitigate a new generation of threats.

Heather Calloway (CISO) — STRONG ACCEPT

This Black Hat talk on mini-app vulnerabilities within super app ecosystems delivers critical insights into a rapidly expanding, yet often overlooked, attack surface. The research meticulously details architectural flaws leading to file system compromises, network credential exfiltration, and the exploitation of hidden APIs, culminating in sophisticated bypasses like prototype chain pollution. This isn't merely a technical exposé; it's a stark reminder of the governance and accountability failures inherent in rapid platform expansion without commensurate security rigor, providing clear, actionable intelligence for super app platform owners and their security leadership.

→ Top-rated talks at Black Hat Asia 2025

All talks from Black Hat Asia 2025