Research
A Malicious Super-App Can Silently Own Every Mini-App Inside It, and Russia's MAX Demonstrates the Full Set
arXiv 2609.11814 (submitted 10 Sep 2026) breaks the assumption underlying a decade of super-app security research, that the host is a trusted intermediary. Using Russia's MAX as the case study, the authors show the host can capture mini-app UI, read and write mini-app local storage, inject arbitrary JavaScript into a mini-app runtime, mediate its network traffic, and control authentication context well enough to enable silent user impersonation, all without leaving a trace. These capabilities follow from architectural privileges every super-app is granted by design, which puts the burden on mobile OS and app store integration rather than on individual mini-app developers.
↳ Follow the thread