Skip to content
Preprint

Exploring Privacy Leakage and Data Disclosure Violations in the MacOS Application Ecosystem

Aug 2026 · 0 citations · 92 references
Computer Science

TL;DR

Analysis of the mechanisms designed to regulate and disclose data collection and sharing practices in the macOS ecosystem reveals how the macOS app ecosystem is comprised of disjoint mechanisms with divergent data abstractions, thus increasing complexity for developers while also facilitating undisclosed privacy-invasive practices.

Abstract

The systematic and excessive data collection practices of tech companies have rendered online privacy both a necessity and a sought-after commodity. However, while the privacy risks of the web, mobile, and IoT ecosystems have been extensively examined, desktop environments have been largely overlooked. As desktop apps continue to be widely used, they remain a critical yet understudied dimension of user privacy. In this paper, we address this gap by presenting the first, to our knowledge, comprehensive study of the mechanisms designed to regulate and disclose data collection and sharing practices in the macOS ecosystem. We adopt an app-development-centric view, and shed light on the interactions between the various macOS mechanisms that mediate apps'data access. Driven by our findings, we develop NutriScan, an analysis framework that incorporates both static and dynamic analysis techniques to create a consolidated view of macOS apps'data practices and disclosures. We use our system to dynamically analyze 1K macOS apps, and find that 85% of them access user-data APIs without disclosing it. 49.7% also exfiltrate data to advertising entities and hosting providers, 12.5% of which do so without a corresponding disclosure. We find that desktop apps are being leveraged by online trackers to enrich user profiles and device fingerprints, thus shedding new light on the true scope of the online tracking ecosystem. Our analysis reveals how the macOS app ecosystem is comprised of disjoint mechanisms with divergent data abstractions, thus increasing complexity for developers while also facilitating undisclosed privacy-invasive practices. Accordingly, we propose a series of mitigations that aim to both streamline the data disclosure process for developers and improve Apple's app vetting process.

View source

Similar papers

Conference Jul 2026

Quantifying and Preventing AI-Aware Privacy Leakage in Large-Scale Data Ecosystems: A Systematic Review

Now, AI runs on cloud platforms, edge systems with federated settings, and in large language model (LLM) pipelines or data-sharing services, creating even wider privacy leakage paths beyond classical database disclosure. This paper offers a systematic, structured review of the literature on a curated, cost-effective re...

Prodip Kumer Das, Amardeep Singh · 0 citations
Preprint Aug 2026

TeleGapper: On the (un)reliability of Privacy Policies in Telegram Mini apps

TeleGapper, a black-box dynamic analysis framework, is presented, a black-box dynamic analysis framework to assess the privacy posture of Mini Apps by capturing runtime network traffic, identifying third-party communications, and comparing observed data flows against disclosed privacy information.

Luca Ferrari, Mariano Ceccato, Luca Verderame · 0 citations
Conference Aug 2026

Security and Forensic Analysis of Dark Web Exploration via the Tor Network

The paper discuss about the utility of anonymity provided by Tor network and evaluate its security and forensic limitations. Whonix was used to create a controlled experimental environment to simulate the use of the dark web anonymously. The study combines network traffic analysis, browser fingerprinting, open-source i...

Tenzin Lungrik, Kbm Tahmiduzzaman, Mahmudur Rahman et al. · 0 citations
Review Aug 2026

SoK: From Generation to Consumption of Privacy Documents in Software Systems

Privacy documents (e.g., privacy policies) are a central mechanism through which digital services disclose data practices and seek user consent. Over the past decades, research on privacy documents has expanded significantly, encompassing not only traditional privacy policies but also short notices (e.g., privacy label...

Shidong Pan, Clark LaChance, Zhenyuan Tao et al. · 0 citations
#federated learning Review Open access Sep 2026

On-Device Privacy and Zero-Knowledge Storage in Mobile Applications: A Review with Attention to Cross-Platform React Native Development

Mobile applications hold the most intimate data that most people generate—messages, health signals, finances, locations, and journals—and the architectural question of where such data live in plaintext has become the defining privacy decision of app design. On-device privacy names one pole of the answer: data is proces...

Serif Oyindamola Oyesiji, Kingsley Chinazaekpere Ndupu, Chukwudera Obumneke Anunagba et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.