Signal Study warns super-app architecture enables covert state-linked surveillance, citing Russia's MAX
Summary
A study challenges a decade of prior security research that has treated super-apps, which host third-party mini-apps inside a single application, as trusted intermediaries. Using Russia's MAX as a case study, whose parent company is reported to be closely tied to state prosecution of online speech, the authors demonstrate that a super-app can silently capture a mini-app's screen, read and write its local storage, and inject arbitrary JavaScript into its runtime. They also show it can intercept network traffic and hijack authentication context to impersonate users without leaving any trace. China's WeChat and Iran's Bale are offered as comparison cases, since WeChat has already been shown to track user activity across mini-apps at scale and Bale has been reported to have state-backed involvement in the world's longest internet shutdown. The study concludes that these surveillance capabilities are not incidental but stem from privileges built into the super-app architecture by design, and it calls for urgent intervention at the mobile operating system and app store level.
Classification
Evidence 1
- Don't Trust the Super-App: A Case Study of Russia's Max arXiv (cs.CY) 2026-09-10 accessed 2026-09-17T05:23:27+00:00
Part of trends 0
No objects.
Directly linked issues 0
No objects.
Public id: fm-88410f2de89a
