A security research paper demonstrates how Russia's MAX super-app can silently compromise mini-app security and user privacy through architectural privileges, including UI capture, storage access, JavaScript injection, and traffic mediation. The study argues that super-apps like WeChat, MAX, and Bale pose inherent risks and calls for mobile OS and app store interventions to address this vulnerability.
Russia has forced tens of millions of citizens to install Max, a super-app developed by VKontakte that combines messaging, payments, and government services. Forensic research reveals Max contains powerful surveillance capabilities including screenshotting, message access, and code injection, functioning as a backdoor into users' devices and mini-apps. The app represents an escalation of digital authoritarianism and a model other authoritarian governments may replicate.
Modular released version 26.6 with Mojo 1.1, opening the Mojo compiler to external contributions under Apache 2.0 license and migrating development to public GitHub. MAX 26.6 adds audio generation support, new model architectures, and significant performance improvements across NVIDIA and AMD GPUs.
A security research paper analyzes vulnerabilities in Russia's MAX super-app, demonstrating how malicious super-apps can compromise mini-app security and user privacy through UI capture, storage access, JavaScript injection, and network mediation. The study argues that super-apps like WeChat, MAX, and Bale present inherent architectural risks and calls for OS and app store interventions to address these vulnerabilities.