Mobile security

Mobile App Security Articles

What this covers

These posts cover Android and iOS application security as it appears in real assessments: what ships inside the package, what lands on the device, how transport protections are bypassed, and why the backing API is usually where the severe findings actually are.

Mobile assessments keep surfacing the same four problems: secrets compiled into the binary, long-lived tokens written to unencrypted storage, transport protections that fail open, and an API that trusts whatever the app sends it. These posts work through each in the order an attacker meets them.

4 posts in Mobile security.

Want this tested properly?

Scope and a fixed quote within two working days. First consultation is free.