Back to results

University of Illinois - Chicago

Evaluation of Security and Privacy Flaws of Cross-platform Android App Development Frameworks

Abstract

dc:description

The increasing adoption of cross-platform mobile development frameworks has markedly simplified the process of creating Android applications; however, it has concurrently introduced significant security and privacy concerns. This thesis provides a comprehensive evaluation of the security and privacy vulnerabilities inherent in widely-used cross-platform Android frameworks, with a focus on Cordova, Ionic and React Native. The study carefully examines the architectural designs and integration patterns of these frameworks to pinpoint common sources of vulnerabilities. To facilitate a systematic assessment, we developed a set of automated scripts for conducting static analyses on decompiled Android applications. Additionally, to perform a large-scale and reproducible evaluation, we collected a dataset of Android applications from publicly available sources, including the AndroZoo database and websites like APKMirror and APKPure. These scripts are designed to detect insecure configurations and known weaknesses in hybrid app implementations. The proposed methodology enables reproducible and scalable testing across various frameworks and application builds. Preliminary analyses reveal that hybrid applications often expose additional attack surfaces compared to their native counterparts, primarily due to the interactions between web and native layers. This research contributes to a deeper understanding of the security implications within hybrid development environments and lays the groundwork for enhancing automated detection techniques for vulnerabilities in cross-platform mobile applications.

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Federico Civitareale (24399359)

Subjects

dc:subject × 1

Rights

dc:rights
Statement dc:rights
  • In Copyright

Identifiers

dc:identifier.*
OAI identifier oai:identifier
oai:figshare.com:article/32993747

Chain of custody

source
Harvested from
University of Illinois - Chicago
Base URL
api.figshare.com/v2/oai
Last updated
2026-07-27
Source record
OAI-PMH GetRecord
related terms
citation

Federico Civitareale (24399359). Evaluation of Security and Privacy Flaws of Cross-platform Android App Development Frameworks. 2026. https://doi.org/10.25417/uic.32993747.v1