Analysis of the mechanisms designed to regulate and disclose data collection and sharing practices in the macOS ecosystem reveals how the macOS app ecosystem is comprised of disjoint mechanisms with divergent data abstractions, thus increasing complexity for developers while also facilitating undisclosed privacy-invasive practices.
Abstract
The systematic and excessive data collection practices of tech companies have rendered online privacy both a necessity and a sought-after commodity. However, while the privacy risks of the web, mobile, and IoT ecosystems have been extensively examined, desktop environments have been largely overlooked. As desktop apps continue to be widely used, they remain a critical yet understudied dimension of user privacy. In this paper, we address this gap by presenting the first, to our knowledge, comprehensive study of the mechanisms designed to regulate and disclose data collection and sharing practices in the macOS ecosystem. We adopt an app-development-centric view, and shed light on the interactions between the various macOS mechanisms that mediate apps'data access. Driven by our findings, we develop NutriScan, an analysis framework that incorporates both static and dynamic analysis techniques to create a consolidated view of macOS apps'data practices and disclosures. We use our system to dynamically analyze 1K macOS apps, and find that 85% of them access user-data APIs without disclosing it. 49.7% also exfiltrate data to advertising entities and hosting providers, 12.5% of which do so without a corresponding disclosure. We find that desktop apps are being leveraged by online trackers to enrich user profiles and device fingerprints, thus shedding new light on the true scope of the online tracking ecosystem. Our analysis reveals how the macOS app ecosystem is comprised of disjoint mechanisms with divergent data abstractions, thus increasing complexity for developers while also facilitating undisclosed privacy-invasive practices. Accordingly, we propose a series of mitigations that aim to both streamline the data disclosure process for developers and improve Apple's app vetting process.
Now, AI runs on cloud platforms, edge systems with federated settings, and in large language model (LLM) pipelines or data-sharing services, creating even wider privacy leakage paths beyond classical database disclosure. This paper offers a systematic, structured review of the literature on a curated, cost-effective re...
TeleGapper, a black-box dynamic analysis framework, is presented, a black-box dynamic analysis framework to assess the privacy posture of Mini Apps by capturing runtime network traffic, identifying third-party communications, and comparing observed data flows against disclosed privacy information.
The paper discuss about the utility of anonymity provided by Tor network and evaluate its security and forensic limitations. Whonix was used to create a controlled experimental environment to simulate the use of the dark web anonymously. The study combines network traffic analysis, browser fingerprinting, open-source i...
Tenzin Lungrik, Kbm Tahmiduzzaman, Mahmudur Rahman et al.· 2026 6th International Confe...· 0 citations
A unified, lifecycle-oriented view of privacy documents from a software engineering perspective is provided, organizing them around five research questions that examine how privacy documents are created, analyzed, evaluated, and maintained across their lifecycle.
Shi-Dong Pan, Clark LaChance, Zhen-Yuan Tao et al.· 0 citations
This review synthesizes the research literature relevant to building such applications, with specific attention to the cross-platform reality in which much of the mobile ecosystem, prominently React Native applications, is actually built, and identifies directions for research and practice.
Serif Oyindamola Oyesiji, Kingsley Chinazaekpere Ndupu, Chukwudera Obumneke Anunagba et al.· Journal of Engineering Resea...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.