Security and Privacy Assessment of U.S. and Non-U.S. Android E-Commerce Applications
Urvashi Kishnani, Sanchari Das
TL;DR
Assesses regional security and privacy practices of top-grossing Android e-commerce apps to understand cross-market differences. The study analyzes 92 apps (58 U.S., 34 international) with MobSF, AndroBugs, and RiskInDroid to address RQ1 and RQ2. The findings reveal widespread SSL weaknesses (92% HTTP), over-privileged permissions, and trackers in a majority of apps, with U.S. apps performing slightly better than non-U.S. counterparts. These results motivate stricter security standards, transparency in permission usage, and privacy-by-design practices, with implications for regulators and developers in the global mobile commerce ecosystem.
Abstract
E-commerce mobile applications are central to global financial transactions, making their security and privacy crucial. In this study, we analyze 92 top-grossing Android e-commerce apps (58 U.S.-based and 34 international) using MobSF, AndroBugs, and RiskInDroid. Our analysis shows widespread SSL and certificate weaknesses, with approximately 92% using unsecured HTTP connections and an average MobSF security score of 40.92/100. Over-privileged permissions were identified in 77 apps. While U.S. apps exhibited fewer manifest, code, and certificate vulnerabilities, both groups showed similar network-related issues. We advocate for the adoption of stronger, standardized, and user-focused security practices across regions.
