Jul 2026· Annual International Computer Software and Applications Conference· pp. 2557-2562· 0 citations· 19 references
Computer Science
Abstract
Cross-platform frameworks such as Flutter and React Native are increasingly adopted in Android application development, yet their security characteristics at scale remain insufficiently understood. In this paper, we present an empirical security characterization of 3,000 Android applications, consisting of 1,000 Flutter-based applications, 1,000 React Native apps, and 1,000 Kotlin-based native applications used as a baseline. Using MobSF and FlowDroid static analysis, we analyze security assessment scores as well as the prevalence of warning-level and high-severity findings across these development ecosystems. The results show consistent but modest differences in average scores and reported finding distributions, with cross-platform applications exhibiting distinct distributional patterns compared to native Kotlin applications. These observations do not imply framework-level vulnerabilities. Rather, they reflect ecosystemlevel tendencies associated with framework architectures, build configurations, and commonly used dependencies. This study characterizes Android security traits reported by static analysis tools and demonstrates that cross-platform and native applications should be interpreted with framework context in mind.
Whether off-the-shelf Large Language Models (LLMs) can effectively reason about taint flows in Android apps is investigated, and preliminary findings suggest that LLM reasoning may effectively complement traditional static taint analysis.
Nicholas Miazzo, Marco Alecci, Jordan Samhi et al.· 0 citations
Software security has been a long-standing and prominent topic in both industry and academia. However, with the increasing deployment of smart devices across various architectures, there is now a significant demand for cross-architecture software. For instance, the Heartbleed vulnerability (CVE-2014-0160), classified a...
Shigang Liu, Di Cao, Chao Chen et al.· IEEE Transactions on Informa...· 0 citations
An automated testing tool named R8Scan is developed that utilizes a novel idea to synthesize seeds from prioritized real-world functions and construct the corresponding arguments empowered by Large Language Models to test R8, thus enabling the exploration of a broader range of semantics.
Zi-Fan Xie, Ming Wen, Shi-Yu Qiu et al.· ACM Transactions on Software...· 0 citations
The rapid adoption of Android applications in mobile commerce has increased exposure to sophisticated malware capable of bypassing traditional security mechanisms through code obfuscation, dynamic code loading, and runtime-triggered malicious behaviors. Although static analysis offers efficient large-scale detection, i...
Cross-platform frameworks and cross-language programming techniques have become the foundation for building modern mobile, desktop, IoT, and cloud applications, while large language models (LLMs) are increasingly used to generate and translate their code. These technologies promise “write once, run anywhere” developmen...
M. Zhou, Yu-Tong Zhang, Jia-Tong Han et al.· ACM Transactions on Software...· 0 citations
This study conducts a large-scale empirical security analysis of the web-based management interfaces of ten widely used open-source Infrastructure-as-a-Service (IaaS) platforms, identifying 16 vulnerabilities spanning nine classes, including high-severity flaws that enable account takeover.
Alexandros Perrakis, Efstratios Chatzoglou, Vyron Kampourakis et al.· International Journal of Inf...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.