A security research paper demonstrates how malicious super-apps, exemplified by Russia's MAX, can silently compromise mini-app security and user privacy through capabilities like UI capture, storage access, and JavaScript injection. The researchers argue that the architectural privileges granted to super-apps by design create vulnerabilities that require urgent intervention from mobile OS and app store providers.