Please wait ...
0% Complete
Home
/
15th International Conference on Computer and Knowledge Engineering
Security Analysis of MiniApps: Vulnerabilities, Exploits, and a Tailored Mitigation Framework
Authors :
Keyhan Mohammadi
1
Arman Moradi
2
Reza Ebrahimi Atani
3
1- Dept. of Computer Engineering University of Guilan Rasht, Iran
2- Dept. of Computer Engineering University of Guilan Rasht, Iran
3- Dept. of Computer Engineering University of Guilan Rasht, Iran
Keywords :
Telegram MiniApps،WebView Exploits،Man in the Middle Attacks،Data Leakage،Sandbox Isolation،Web3Auth
Abstract :
Telegram MiniApps and WeChat Mini Programs represent two leading implementations of the superApp sub application paradigm, each combining centralized backend ser- vices with lightweight, embedded client interfaces. While both platforms enable rich user experiences, they also introduce significant security risks through architectural and implemen- tation flaws. In this paper, we present a comparative analysis of vulnerabilities in Telegram MiniApps and WeChat Mini Programs, drawing from documented exploits and empirical testing. For WeChat, prior studies reveal widespread issues including sensitive data leakage, weak permission enforcement, and cross MiniApp request forgery, affecting millions of deployed apps. For Telegram, we identify unproxied frontend–backend communication leaking IPs and server endpoints, insecure HTTP defaults in the Bot API enabling man in the middle attacks, and inadequate auditing of TON blockchain smart contracts. We further analyze adversarial MiniApps exploiting WebView sandbox weaknesses for malware delivery, cryptomining, and cryptocurrency phishing. Building on these findings, we propose a comprehensive mitigation framework tailored to Telegram but informed by lessons from WeChat’s vulnerabilities. Our approach includes mandatory HTTPS, Telegram-hosted proxying, sandbox isolation, automated malicious activity detection, and AI-assisted code auditing. The results highlight the urgent need for platform level reforms across superApp ecosystems to align rapid feature growth with strong user privacy and security guarantees.
Papers List
List of archived papers
Online Task Offloading and Scheduling in Fog-Cloud Environment based on Reinforcement Learning
Ali Sheidaee - Leili Farzinvash - Alireza Sokhandan
An Interactive Approach for Query-based Multi-Document Scientific Text Summarization
Mohammadsadra Nejati - Azadeh Mohebi - Abbas Ahmadi
Efficient Prediction of Cardiovascular Disease via Extra Tree Feature Selection
Mina Abroodi - Mohammad Reza Keyvanpour - Ghazaleh Kakavand Teimoory
Real-time Implementation of Fuzzy Visual Servoing for a Delta Robot via Shape and Color Detection
Nooshin Najafian - Alireza Ashrafi Majd - Abbas Ansaroudi - Sahar Aghazadeh - Manizheh Zakeri - Mohammad-Reza Sayyed Noorani
User Behavior Analysis : A Framework for Web Systems with Adaptive User Interfaces Using Unsupervised Modeling
Ali Bajelan - Ehsan Khadangi (Corresponding Author)
Paddy Plant Stress Identification Using Few-Shot Learning Framework
Ervin Gubin Moung - Pavindrah Naidu a/l Narayanasamy Naiidu - Maisarah Mohd Sufian - Valentino Liaw - Ali Farzamnia - Lorita Angeline
Multi-Digit Handwritten Recognition: A CNN-LSTM Hybrid Approach with Wavelet Transforms
Amin Kazempour - Jafar Tanha
A Dual-Branch Attention-Enhanced CNN for Corn Leaf Disease Classification via RGB-HLS Color Space Fusion
Mohammad Ali Salehi Rad - Kamran Kazemi - Mohammad Sadegh Helfroush - Tahereh Golshaeian
Binary Classification of Capuchin Bird Calls via Spectrogram-Enhanced Frequency-Aware Convolutional Neural Networks
Samad Najjar-Ghabel - Shamim Yousefi - Reza Danandeh Bileh Savar
BERT transformers Multitask learning Sarcasm and Sentiment classification (BMSS)
Fatemeh Molavi - Jamshid Bagherzadeh Mohasefi
more
Samin Hamayesh - Version 44.9.3