3 papers
cs.CR2026
(A)I Sees What You Don't: Exploiting New Attack Surfaces in Third-Party Mobile Agents
Zidong Zhang, Zhentao Xie, Wenrui Diao +1
Third-party mobile agents powered by Vision-Language Models (VLMs) have emerged as a promising paradigm for automating smartphone interactions. These agents act as high-privilege d…
cs.CR2026
Mini-Programs, Mega-Problems: Unveiling OAuth-based Authentication Misuses in Mini-Programs via Dynamic Analysis
Zidong Zhang, Zhentao Xie, Lingyun Ying +4
Mini-programs have become a dominant paradigm for lightweight application deployment within super apps such as WeChat. To support seamless integration, super apps provide OAuth mec…
cs.CR2025
Control at Stake: Evaluating the Security Landscape of LLM-Driven Email Agents
Jiangrong Wu, Yuhong Nan, Jianliang Wu +2
The increasing capabilities of LLMs have led to the rapid proliferation of LLM agent apps, where developers enhance LLMs with access to external resources to support complex task e…