A security research paper demonstrates how Russia's MAX super-app can silently compromise mini-app security and user privacy through architectural privileges, including UI capture, storage access, JavaScript injection, and traffic mediation. The study argues that super-apps like WeChat, MAX, and Bale pose inherent risks and calls for mobile OS and app store interventions to address this vulnerability.