{"id":{"repo_id":"uic","oai_identifier":"oai:figshare.com:article/32993747"},"canonical_url":"https://search.dev.ndltd.org/etd/uic/oai:figshare.com:article/32993747","repository":{"repo_id":"uic","name":"University of Illinois - Chicago","base_url":"https://api.figshare.com/v2/oai"},"display":{"title":"Evaluation of Security and Privacy Flaws of Cross-platform Android App Development Frameworks","abstract":"The increasing adoption of cross-platform mobile development frameworks has markedly simplified the process of creating Android applications; however, it has concurrently introduced significant security and privacy concerns. This thesis provides a comprehensive evaluation of the security and privacy vulnerabilities inherent in widely-used cross-platform Android frameworks, with a focus on Cordova, Ionic and React Native. The study carefully examines the architectural designs and integration patterns of these frameworks to pinpoint common sources of vulnerabilities. To facilitate a systematic assessment, we developed a set of automated scripts for conducting static analyses on decompiled Android applications. Additionally, to perform a large-scale and reproducible evaluation, we collected a dataset of Android applications from publicly available sources, including the AndroZoo database and websites like APKMirror and APKPure. These scripts are designed to detect insecure configurations and known weaknesses in hybrid app implementations. The proposed methodology enables reproducible and scalable testing across various frameworks and application builds. Preliminary analyses reveal that hybrid applications often expose additional attack surfaces compared to their native counterparts, primarily due to the interactions between web and native layers. This research contributes to a deeper understanding of the security implications within hybrid development environments and lays the groundwork for enhancing automated detection techniques for vulnerabilities in cross-platform mobile applications.","abstract_html":"The increasing adoption of cross-platform mobile development frameworks has markedly simplified the process of creating Android applications; however, it has concurrently introduced significant security and privacy concerns. This thesis provides a comprehensive evaluation of the security and privacy vulnerabilities inherent in widely-used cross-platform Android frameworks, with a focus on Cordova, Ionic and React Native. The study carefully examines the architectural designs and integration patterns of these frameworks to pinpoint common sources of vulnerabilities. To facilitate a systematic assessment, we developed a set of automated scripts for conducting static analyses on decompiled Android applications. Additionally, to perform a large-scale and reproducible evaluation, we collected a dataset of Android applications from publicly available sources, including the AndroZoo database and websites like APKMirror and APKPure. These scripts are designed to detect insecure configurations and known weaknesses in hybrid app implementations. The proposed methodology enables reproducible and scalable testing across various frameworks and application builds. Preliminary analyses reveal that hybrid applications often expose additional attack surfaces compared to their native counterparts, primarily due to the interactions between web and native layers. This research contributes to a deeper understanding of the security implications within hybrid development environments and lays the groundwork for enhancing automated detection techniques for vulnerabilities in cross-platform mobile applications.","abstract_has_math":false,"creators":["Federico Civitareale (24399359)"],"institution":null,"degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2026,"date_issued":"2026-05-01T00:00:00Z","date_published":"2026-05-01T00:00:00Z","updated_at":"2026-07-27T21:33:36Z","subjects":["mobile frameworks"],"languages":[],"rights":["In Copyright"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://doi.org/10.25417/uic.32993747.v1","outbound_label":"DOI","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Federico Civitareale (24399359)"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2026-05-01T00:00:00Z"]},{"key":"dc:relation","label":"Dc Relation","values":["https://figshare.com/articles/thesis/Evaluation_of_Security_and_Privacy_Flaws_of_Cross-platform_Android_App_Development_Frameworks/32993747"]},{"key":"dc:type","label":"Dc Type","values":["Text","Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["mobile frameworks"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["In Copyright"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["10.25417/uic.32993747.v1"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["The increasing adoption of cross-platform mobile development frameworks has markedly simplified the process of creating Android applications; however, it has concurrently introduced significant security and privacy concerns. This thesis provides a comprehensive evaluation of the security and privacy vulnerabilities inherent in widely-used cross-platform Android frameworks, with a focus on Cordova, Ionic and React Native. The study carefully examines the architectural designs and integration patterns of these frameworks to pinpoint common sources of vulnerabilities. To facilitate a systematic assessment, we developed a set of automated scripts for conducting static analyses on decompiled Android applications. Additionally, to perform a large-scale and reproducible evaluation, we collected a dataset of Android applications from publicly available sources, including the AndroZoo database and websites like APKMirror and APKPure. These scripts are designed to detect insecure configurations and known weaknesses in hybrid app implementations. The proposed methodology enables reproducible and scalable testing across various frameworks and application builds. Preliminary analyses reveal that hybrid applications often expose additional attack surfaces compared to their native counterparts, primarily due to the interactions between web and native layers. This research contributes to a deeper understanding of the security implications within hybrid development environments and lays the groundwork for enhancing automated detection techniques for vulnerabilities in cross-platform mobile applications."]},{"key":"dc:title","label":"Title","values":["Evaluation of Security and Privacy Flaws of Cross-platform Android App Development Frameworks"]}]}],"canonical_facts":{"dc:creator":["Federico Civitareale (24399359)"],"dc:date":["2026-05-01T00:00:00Z"],"dc:description":["The increasing adoption of cross-platform mobile development frameworks has markedly simplified the process of creating Android applications; however, it has concurrently introduced significant security and privacy concerns. This thesis provides a comprehensive evaluation of the security and privacy vulnerabilities inherent in widely-used cross-platform Android frameworks, with a focus on Cordova, Ionic and React Native. The study carefully examines the architectural designs and integration patterns of these frameworks to pinpoint common sources of vulnerabilities. To facilitate a systematic assessment, we developed a set of automated scripts for conducting static analyses on decompiled Android applications. Additionally, to perform a large-scale and reproducible evaluation, we collected a dataset of Android applications from publicly available sources, including the AndroZoo database and websites like APKMirror and APKPure. These scripts are designed to detect insecure configurations and known weaknesses in hybrid app implementations. The proposed methodology enables reproducible and scalable testing across various frameworks and application builds. Preliminary analyses reveal that hybrid applications often expose additional attack surfaces compared to their native counterparts, primarily due to the interactions between web and native layers. This research contributes to a deeper understanding of the security implications within hybrid development environments and lays the groundwork for enhancing automated detection techniques for vulnerabilities in cross-platform mobile applications."],"dc:identifier":["10.25417/uic.32993747.v1"],"dc:relation":["https://figshare.com/articles/thesis/Evaluation_of_Security_and_Privacy_Flaws_of_Cross-platform_Android_App_Development_Frameworks/32993747"],"dc:rights":["In Copyright"],"dc:subject":["mobile frameworks"],"dc:title":["Evaluation of Security and Privacy Flaws of Cross-platform Android App Development Frameworks"],"dc:type":["Text","Thesis"]},"updated_at":"2026-07-27T21:33:36Z"}