Russian app «Max» turned out to be a ‘backdoor’ in a smartphone: what it can see

The platform is capable of managing the data and authorisation for its mini-programmes, taking screenshots of their interfaces and deploying code.

0

Max, the Russian state-run messaging app, which the authorities are actively transforming into a universal platform for messaging, payments and public services, has the technical capability to covertly monitor users’ activities within its mini-apps. Researchers from universities in the US, Canada and India have found that the platform can capture screen content, read and modify the local data of mini-apps, control authorisation and even inject its own code. However, the study demonstrates Max’s technical capabilities rather than proving that Russian intelligence services have already used each of them against specific users.

Key points at a glance:

  • Researchers analysed the Russian app Max.
  • He can view the content of his mini-programmes.
  • The platform is capable of taking screenshots of the interface without the user’s knowledge.
  • Max is being actively integrated into public services and education.
  • At the same time, other messaging apps are being restricted in the Russian Federation.
Add UkrMedia to your Google sources Get more of our news in the recommendations.

What did the researchers at Max discover?

Research work Don’t Trust the Super-App: A Case Study of Russia’s Max was published in September. Its authors examined the Max architecture and the ways in which the main application interacts with so-called ‘mini-apps’ — small programmes that run directly within the platform.

According to the analysis, Max has privileged access to the following mini-programmes and is technically capable of:

  • capture screenshots of the mini-programme interface;
  • read and modify their local storage;
  • to integrate JavaScript into the operation of mini-programmes;
  • monitor their network traffic;
  • manage the user’s authorisation context.

According to the authors of the study, this final option potentially enables the platform to to impersonate a user without their knowledge. The researchers also warn that the ability to execute arbitrary code could, in theory, be exploited for other malicious purposes.

Professor at the University of Michigan Roya Ensafi, who took part in the study, said Max an example of a particularly dangerous model of control via a «super-app». The Guardian notes that this kind of architecture makes it possible to combine private messaging, payments, banking transactions and government services within a single app.

Can Max read Telegram and WhatsApp?

There is an important limitation. Researchers It has not been established that Max can directly access separately installed Telegram or WhatsApp apps and read their messages. The opportunities identified relate primarily to the Max ecosystem itself and the mini-programmes that run within it.

However, the significance of this restriction is diminished by the policies of the Russian authorities. In Russia WhatsApp Telegram has faced increasingly stringent restrictions over the past year, whilst other popular services have already been blocked or significantly slowed down. At the same time, the Kremlin is promoting Max as a «national messaging app».

Max has been made compulsory for new smartphones

From. On 1 September 2025, Russia required manufacturers and retailers to pre-install Max on smartphones and tablets sold in the country. The authorities attributed this to the development of domestic digital services. Critics, however, warned that concentrating communications and public services on a single platform increases the scope for surveillance.

In 2026, integration went even further. The Russian authorities announced that digital communication in schools would be switched to Max. In March, the Russian Minister of Education, Sergey Kravtsov, stated that all Russian schools — totalling over 20 million pupils and teachers — had switched to the platform.

Max is also being used to expand access to public services and digital identification. In particular, Russian legislation has permitted the use of the digital ID generated in Max to verify a person’s identity in a number of situations.

Staff and students report being subjected to pressure

The Guardian quotes accounts from Russians who claim that they had virtually no choice but to install the programme.

A teacher at a Moscow school told the publication that the school administration had moved communication with parents, homework assignments and other work-related communication to Max. A student from St Petersburg said he had installed the app after being warned of possible problems accessing university buildings and halls of residence without a QR code.

That said, the Russian Ministry of Digital Development had previously stated officially that the use of Max in educational institutions is «entirely voluntary» and the law does not require compulsory registration with it in order to receive an education.

There is, therefore, a marked difference between official statements regarding voluntary participation and reports on practices in individual institutions.

Max’s audience already numbers in the tens of millions

According to figures cited by Russian officials and the developer, in March Max had around 100 million registered users and approximately 70 million daily active users.

Over the summer, major Russian operators also made data transfers within Max free of charge for subscribers. Representatives of the telecoms companies described the platform as part of Russia’s state digital infrastructure.

In July, the European Union imposed sanctions on VK in connection with the development of Max. In its justification for the sanctions, the EU stated that the development of the app had been overseen by the FSB and that the platform had significant capabilities for monitoring communications.

Why are researchers talking about a «backdoor»?»

In a standard smartphone model, different apps are isolated from one another by the Android operating system or iOS. But many of the services in the «super-app» are operational within a single main programme.

It is this app that acts as an intermediary between the user and dozens of mini-services.

Researchers believe that this poses a fundamental problem: the user must place their complete trust in the owner of the main platform. If the operator of a super-app decides to use its privileges for surveillance, the average user might not even notice.

That is precisely why the authors of the paper cite the Max architecture as an example «blind spots» in mobile platform security and are calling on Google, Apple and operating system developers to introduce further restrictions on super-apps.

WRITE A REPLY

enter your comment!
enter your name here