Top Mobile App Threats of 2025: What Half a Million Assessments Reveal
At RSAC 2025, NowSecure co-founder Andrew Hoog presented findings from over half a million mobile app security assessments conducted between January 2022 and February 2025, revealing widespread vulnerabilities in apps from official app stores. The top five risks identified include insufficient resilience against static analysis, with nearly 75% of apps leaving debug symbols in their code, 87% having API discovery issues, and 68% exposing hardcoded URLs. Outdated and insecure encryption methods were prevalent, with over 60% of apps using weak cryptography, such as Triple DES, and practices like reusing initialization vectors and hardcoding encryption keys. Additionally, many apps incorporated untested and vulnerable third-party SDKs, posing further security risks. These findings underscore the critical need for developers to adopt robust security practices and for organizations to rigorously assess the security of mobile applications, even those sourced from trusted app stores.
https://www.scworld.com/news/rsac-2025-top-5-mobile-app-risks-revealed-by-half-a-million-assessments
Comments
Post a Comment