TENET:Telegram迷你应用(不)安全性
TENET: Telegram Mini App (in)security
浏览论文内容
中文总结 AI 辅助
本文针对Telegram迷你应用生态系统的独特安全风险,开发了专用审计工具TENET,筛查发现37款应用中30款存在安全漏洞,推动Telegram修复了官方钱包的严重漏洞并提出相关安全措施。
中文摘要 AI 辅助
Telegram拥有超过4.5亿日活跃用户,已推出迷你应用(Mini Apps)——直接在其客户端内运行的基于网页的应用程序。然而,这种集成引入了显著的安全风险。正如我们所展示的,许多迷你应用将认证材料(如会话令牌和钱包助记词)以明文形式存储在客户端设备上,使用户面临未授权访问、身份冒充和金融剥削的风险。虽然不安全的客户端存储是网页应用中已知的风险,但Telegram迷你应用生态系统呈现出先前研究中不存在的独特危险因素组合:无平台级安全审查、无存储访问限制、处理实时加密资产的具有金融动机的用户群体,以及比独立浏览器提供更弱保护的WebView环境。为了调查这一威胁,我们提出了TENET,一款专用审计工具,其设计决策(模式选择、熵阈值和字符集验证)基于目标秘密的结构属性,并针对真实数据集进行了经验验证。我们使用基于流行度的分层、流行度加权抽样策略筛选了61个迷你应用。在符合我们处理标准并被分析的37个应用中,有30个存在安全漏洞,我们将这些漏洞分为三个严重程度层级:明文存储、可恢复加密和可重放令牌。值得注意的是,即使是Telegram官方钱包也存在可能导致完全账户入侵的严重漏洞。在我们进行负责任披露后,Telegram实施了两个新的安全存储API,我们的修复后验证确认其官方钱包不再以明文形式暴露恢复助记词。最后,我们为Telegram平台开发者和第三方迷你应用创建者提出了缓解措施和最佳实践。
英文摘要
Telegram, with over 450 million daily active users, has introduced Mini Apps---web-based applications running directly within its client. However, this integration introduces notable security risks. As we demonstrate, many Mini Apps store authentication materials---such as session tokens and wallet mnemonic phrases---in plaintext on client devices, exposing users to unauthorized access, impersonation, and financial exploitation. While insecure client-side storage is a known risk in web applications, the Telegram Mini App ecosystem presents a uniquely dangerous combination of factors absent from prior work: no platform-level security review, no storage access restrictions, a financially motivated user base handling live cryptocurrency assets, and a WebView environment that offers weaker protections than standalone browsers. To investigate this threat, we present TENET, a purpose-built auditing tool whose design decisions---pattern selection, entropy thresholds, and charset validation---are grounded in the structural properties of the secrets targeted and empirically validated against a ground-truth dataset. We screened 61 Mini Apps using a stratified, popularity-weighted sampling strategy based on popularity. Of the 37 applications that met our processing criteria and were analyzed, 30 exhibited security flaws, which we classify into three severity tiers: plaintext storage, recoverable encryption, and replayable tokens. Notably, even Telegram's official Wallet exhibits a severe vulnerability that may lead to full account compromise. Following our responsible disclosure, Telegram implemented two new secure-storage APIs, and our post-remediation verification confirmed that its official Wallet no longer exposes the recovery mnemonic in plaintext. Finally, we propose mitigation measures and best practices for both Telegram platform developers and third-party Mini App creators.