appsec.fyi

Mobile Security Resources

Post Share

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Mobile Security

Mobile application security encompasses the unique attack surface of iOS and Android applications, including insecure local data storage, weak transport layer protection, insufficient binary protections, and client-side injection vulnerabilities. The OWASP Mobile Top 10 highlights risks such as improper platform usage, insecure data storage, insecure communication, insecure authentication, insufficient cryptography, and code tampering. Mobile apps face threats that web applications do not: reverse engineering of client-side code, certificate pinning bypass, inter-process communication attacks, and exploitation of platform-specific features like deep links, content providers, and keychain storage. Tools like Frida, objection, MobSF, and Jadx enable dynamic instrumentation and static analysis of mobile binaries, while proxy tools allow interception of API traffic for server-side testing.

Mobile testing is mostly a fight to see the traffic

The analysis itself is not conceptually different from web work — the same authorization, injection and business-logic classes apply, because the same backend is usually serving both. What differs is access. On the web the browser shows you everything; on a mobile device the client is a compiled binary you do not control, running on a platform designed to resist exactly the inspection you are trying to do. A large share of the material here is about getting to a position where testing can start.

That means interception first. Installing a trusted CA certificate is step one, and on modern Android it is immediately complicated by the user-CA trust changes, so a rooted device or a repackaged app is typically required. Certificate pinning is step two, defeated by patching the binary, hooking the verification routine at runtime with Frida or Objection, or substituting the pinned material. None of this is exotic any more, but it is fiddly and version-dependent, and the writeups that specify platform versions are the useful ones.

Once traffic is visible, the highest-yield areas are local data and platform integration. Applications store far more than intended in shared preferences, SQLite databases, plists, caches, logs and backups — session tokens, PII and occasionally credentials. Keychain and Keystore usage is frequently misconfigured in ways that make hardware protection decorative. Exported activities, services, content providers, deep links and custom URL schemes are an IPC attack surface with no web analogue, and they are a common route to actions the app intended to keep internal.

Static analysis of the package is worth doing early: decompiled code and resources routinely contain hardcoded API keys, endpoint lists including staging environments, debug flags and feature toggles.

A caution worth stating — client-side controls are advisory. Root and jailbreak detection, obfuscation and pinning raise cost and are not security boundaries; the server must assume a hostile client.

Start here: the Mobile learning pathAn ordered route through this library — orientation, then methodology, then research. Read the Mobile guideA long-form, source-cited deep dive synthesized from every resource below. The comprehensive Mobile guide on chs.usA hand-written, in-depth practitioner guide — attacks, testing, and prevention.
Date Added Link Excerpt
2026-10-08 NEW 2026Presenting DiagNG: After QCSuper, a new open-source initiative for freeing up mobile baseband Diag protocols advancedDiagNG is a new open-source initiative designed to unblock mobile baseband Diag (diagnostic) protocols. Building on the legacy of QCSuper, DiagNG aims to provide greater accessibility and functionality for developers working with mobile device communication. This project focuses on making these powerful diagnostic tools more readily available for research and development.
2026-09-29 2026How we found 24 Android vulnerabilities using our open source AI security agent intermediate 10 min read AILibrary for automating and sharing AI-driven security research workflows, enabling researchers to craft custom prompts for LLMs to discover vulnerabilities in applications. It includes specific taskflows like `gather_mobile_entry_point_info` and `classify_application_local`, which help identify mobile-specific entry points and check for vulnerability classes such as confused deputy and insecure broadcasts. This approach has successfully identified over 20 vulnerabilities in Android applications, including examples like location tracking and route data exfiltration in OsmAnd. → github.blog
2026-09-27 2026EX-ARRR: Sailing the Apple 0-click Seas advanced 19 min readLibrary for discovering zero-click vulnerabilities in Apple devices, focusing on heap overflows within image parsers. This resource details the exploitation of a four-byte-per-pixel buffer overrun in Apple's EXR decoder, libAppleEXR.dylib, which is triggered by malformed OpenEXR image files. The technique leverages LLM-guided fuzzing to identify memory safety bugs and a path to reach the vulnerable parser without user interaction, bypassing BlastDoor and requiring no user taps for execution.
2026-09-26 2026CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2 advanced 13 min readWriteup detailing the exploitation of CVE-2025-13032, a double-fetch vulnerability in Avast Antivirus. This technical article walks through achieving arbitrary kernel read/write on Windows 11 by corrupting the `RegBuffers` array of an I/O Ring Object. Techniques include heap spraying, kernel address leaking via MDL introspection, and SYSTEM privilege escalation through token theft, building upon a paged pool overflow.
2026-09-25 2026Lunex Unmasked: A New Information Stealer Deployed Through BYOVD intermediate 17 min read Supply ChainLibrary analyzing Lunex, a Malware-as-a-Service platform, detailing its four-stage attack chain targeting Ukrainian-speaking users. The analysis covers the MSI installer, a loader/dropper employing Bring Your Own Vulnerable Driver (BYOVD) abuse for privilege escalation and disabling kernel-level security, and the Lunex Stealer which functions as a C2 agent. It also details credential theft from Chromium browsers, cryptocurrency wallet exfiltration, persistent backdoor installation, and the platform's C2 infrastructure originating from a CIS-aligned, financially motivated threat actor.
2026-09-25 2026CDC-ACM Serial Interface Bypasses TCC on macOS intermediate 16 min read AuthZLibrary implementing a bypass of macOS's TCC (Transparency, Consent, and Control) for CDC-ACM serial interfaces, allowing unauthorized access to credentials like SSH keys and cloud logins. This bypass affects any Mac that has ever approved a USB hub, dock, or adapter, enabling a malicious USB device to exfiltrate sensitive data within seconds without user notification, even with Lockdown Mode enabled. The technique targets a fundamental trust relationship established between macOS and peripheral devices.
2026-09-25 2026Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL advanced 10 min read RCELibrary for rooting OnePlus 15 running OxygenOS 16 by chaining two vulnerabilities: an audio debug service allowing arbitrary command execution via `system()`, and a vendor HAL exposing a `doShell` function callable by root UIDs. This library enables an untrusted app to achieve root access by first exploiting the audio debug service to gain root privileges in the `dumpstate` SELinux domain, and then using those privileges to call the vendor HAL's `doShell` function, which executes commands with the highly privileged `vendor_qti_init_shell` SELinux context and full Linux capabilities.
2026-09-25 2026One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts intermediate 4 min read AuthZWriteup on CVE-2026-13795, detailing how Chrome for iOS could be bypassed to trigger arbitrary URL schemes, including `tel:` and `facetime:`, via Apple Shortcuts. By leveraging Shortcuts' `x-callback-url` functionality, a malicious webpage could chain a navigation to the Shortcuts app with a subsequent callback to a sensitive URL, bypassing Chrome's app-launch confirmation prompts and user interaction checks. This vulnerability allowed a single click to initiate actions like phone calls without explicit user consent for the final destination. → blog.doyensec.com
2026-09-25 2026Unified Code, Unified Risks: Uncovering Vulnerabilities in .NET MAUI Applications intermediate 9 min readLibrary for analyzing .NET MAUI applications, enabling the extraction of readable C# assemblies from both Android and iOS builds. It leverages the `mauidll` tool to streamline the process of locating and decompressing LZ4-compressed DLLs from non-standard ELF sections within Android APKs, allowing for static analysis of shared logic. This facilitates uncovering vulnerabilities by treating cross-platform codebases with a single extraction pipeline, applicable to both platforms for identifying critical flaws. → bishopfox.com
2026-09-24 2026Inside Corp MDM, the Android spyware targeting logistics companies news 8 min readLibrary for analyzing "Corp MDM," an Android spyware campaign targeting the logistics sector. The library details how this implant, disguised as system services via fake Google Play pages for CEVA and TKW Logistics, exfiltrates SMS content, diverts calls using USSD codes, and maintains persistence. It highlights the campaign's use of a common C2 server at 69.55.61.82, also used for phishing and Windows malware, potentially linking to Armenian and Russian threat actors involved in cargo theft.
2026-09-24 2026Android 17 enables certificate transparency, and breaks custom CAs news 11 min readLibrary for intercepting Android traffic, addressing changes in Android 17 that enable certificate transparency by default. This update mandates that all system-trusted certificates must include Signed Certificate Timestamps (SCTs) to be trusted by apps targeting API level 37. This requirement breaks custom Certificate Authority (CA) configurations and self-signed certificates commonly used for debugging and security research, including those employed by tools like HTTP Toolkit. The library provides a solution for developers and researchers needing to overcome these new restrictions, particularly for local network debugging and custom CA setups.
2026-09-22 2026ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553 news 12 min read AuthNWriteup of CVE-2026-86553 and related vulnerabilities in the ZTE SmartLife app, affecting over 100,000 Android downloads. The research uncovered issues stemming from recoverable trust material within the mobile client, enabling account-sensitive operations on the backend without proper user authorization. Key findings include a password reset flaw rated CVSS 8.8, and vulnerabilities related to AES-GCM encryption with hardcoded and recovered keys.
2026-09-17 2026Atomic macOS (AMOS) Stealer Activity beginner 6 min read SecretsAnalysis of Atomic macOS (AMOS) Stealer details a lab-generated infection occurring on August 5, 2026. This macOS information stealer, advertised on Telegram, exfiltrates system information, login credentials, and sensitive data from applications like browsers and cryptocurrency wallets. AMOS stealer is distributed via ClickFix campaigns and malicious ads offering cracked software, utilizing Zsh scripts and Mach-O binaries for installation. Post-infection, it communicates with C2 servers and collects data including wallet information and credentials, with evolving indicators and infrastructure making it a persistent threat. → unit42.paloaltonetworks.com
2026-09-13 2026Locating Flutter's TLS certificate verifier in a stripped libflutter.so without byte signatures advanced 5 min readTool for locating Flutter's TLS certificate verifier function, `ssl_crypto_x509_session_verify_cert_chain`, within stripped `libflutter.so` binaries without relying on brittle byte signatures. This technique leverages specific code behaviors like referencing the `ssl_client` and `ssl_server` strings and an out-pointer for an alert code, demonstrated to work across multiple Flutter app versions and engines. The tool's application revealed a bug in the author's own patcher when encountering apps that deviate from typical APK structure.
2026-09-11 2026Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability news AuthZOnePlus's preinstalled OEM app has a session takeover vulnerability, which has remained unresolved for over nine months. Following a vendor request, technical details were temporarily removed offline but will be re-published soon. This indicates a limited window for OnePlus to fix the issue before full disclosure. The researchers emphasize responsible disclosure practices, expecting the vendor to also act responsibly. No specific payout amount is mentioned. → blog.doyensec.com
2026-09-09 2026WeWorm - The first zero-click worm to spread through WeChat calls across iOS and Android. advanced 4 min readWriteup detailing WeWorm, the first zero-click worm to spread via WeChat calls across iOS and Android. This research highlights a memory corruption bug in WeChat's VoIP stack, allowing full account takeover without user interaction. The exploit, discovered by AI and developed by Calif, demonstrates how advanced attack capabilities can be rapidly weaponized, emphasizing the need for industry-wide collaboration and AI-assisted defense. Tencent has since mitigated the vulnerability.
2026-09-09 2026Payment Bypass Flaw in TechPSC HUB intermediate API SecA security researcher discovered a payment bypass vulnerability in the TechPSC HUB Android app. While set 4 of a quiz is supposed to trigger a subscription payment, disabling the internet connection during quiz selection allowed users to access it without paying. The researcher identified leaked APIs by decompiling the app. → infosecwriteups.com
2026-09-03 2026Android App RCE via Dynamic Code Loading intermediate RCEThis blog post details how to achieve Remote Code Execution (RCE) in an Android document viewer app. The exploit leverages a path traversal vulnerability combined with dynamic code loading. The author refers to a previous vulnerability in Adobe Acrobat Reader for Android (CVE-2021–40724) as a reference, also mentioning previous work on insecure content providers and hijacking the Android notification system. The post focuses on exploring the app's functionality to understand its attack surface. No specific bounty payout amount is mentioned. → infosecwriteups.com
2026-09-01 2026EncryptedSharedPreferences is Dead: Here’s What You Should Use Instead intermediate 17 min readLibrary for secure Android data storage. It addresses the deprecation of EncryptedSharedPreferences and Jetpack Security Crypto, recommending developers instead use Jetpack DataStore paired with Google Tink for direct cryptographic operations. This approach provides greater control and visibility into data transformation and storage, overcoming inconsistencies previously seen with EncryptedSharedPreferences and the Android Keystore. → blog.includesecurity.com
2026-08-19 2026How a popular Android library silently exposed thousands of apps to Arbitrary File Overwrite (AFO). https://itis911.github.io/writeups/cropper-vulnerability.html intermediate 6 min readLibrary detailing an Arbitrary File Overwrite (AFO) vulnerability in the `com.canhub:android-image-cropper` library. The vulnerability arises from the library's default manifest configuration, specifically an `android:exported="true"` Activity and root-scoped `<paths>` in its `FileProvider`. This combination allows any installed app to craft an intent, providing a malicious source URI and an attacker-controlled output URI. The library then decodes an image, re-encodes it, and writes it to the specified output, effectively enabling file overwrites that could lead to account takeover via configuration corruption or, in specific non-standard loading scenarios, code execution by replacing native libraries.
2026-08-17 2026Why Protocol Matters: Evil PWA Attack on Casdoor advanced 3 min read API Sec AuthNWriteup detailing an "Evil PWA Attack" exploiting a vulnerability in Casdoor's origin validation. The technique bypasses checks on `redirect_uri` by leveraging custom protocol handlers within Progressive Web Apps (PWAs). This allows an attacker to trick users into installing a malicious PWA, which can then intercept authentication codes due to the improper validation of origins like `web+slonser://z.chromiumapp.org`, ultimately enabling user data theft across multiple platforms.
2026-08-12 2026Kimwolf v7: An Evolution of the Kimwolf Botnet advanced 11 min readLibrary detailing Kimwolf v7, an upgraded Android/IoT botnet that targets Android TV boxes and set-top boxes. Kimwolf v7 enhances distributed denial-of-service (DDoS) attacks with an HTTP/2 flood using the nghttp2 library, making attack traffic harder to distinguish from legitimate browsing. Its command-and-control (C2) infrastructure leverages hard-coded Ethereum Name Service (ENS) domains resolved via public Ethereum RPC endpoints, and includes a Tor .onion hidden service as a fallback. The malware spreads by exploiting unauthenticated Android Debug Bridge (ADB) instances on local networks. → unit42.paloaltonetworks.com
2026-08-08 2026TrustFall: When the Trusted Execution Environment Cannot Be Trusted news 12 min readLibrary for securing Trusted Execution Environments (TEEs) like OP-TEE, which protects sensitive data on Arm devices. It addresses vulnerabilities within the OP-TEE core, including a heap underwrite bug in the RSA NOPAD encryption path. This bug, triggered by an oversized input during modular exponentiation, allows an attacker to corrupt the heap by overwriting free list pointers, enabling a write-what-where primitive and subsequent code execution within the Secure World. The library details techniques for exploiting memory corruption, leaking addresses to defeat ASLR, and manipulating the BGET allocator's free list.
2026-08-01 2026The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version advanced 17 min read Supply ChainAnalysis of XCSSET v40, a macOS malware, reveals its advanced stealth techniques including polymorphic payload generation, fileless persistence, and in-memory execution. This version, distributed through supply chain attacks via Xcode projects, features enhanced worming capabilities and a multi-layered cipher shift for obfuscation. Researchers used AI and pattern-matching to de-obfuscate its logic, uncovering new modules like a Chrome hijacking backdoor leveraging the Chrome DevTools Protocol (CDP) for arbitrary JavaScript execution and credential theft, and a Telegram trojanizer. XCSSET v40's infection chain involves four stages, culminating in memory-resident core modules that execute specialized components for browser hijacking, credential theft, and data exfiltration. → unit42.paloaltonetworks.com
2026-07-30 2026Reversing of Eufy Security Video Doorbell sync protocol and wifi creds decryption from flash memory advanced 27 min readLibrary for reversing the Eufy Security Video Doorbell. This work details the soundwave sync protocol, jamming capabilities by deauthenticating the device from its hidden Wi-Fi network, and the extraction and decryption of Wi-Fi credentials from flash memory. It targets the OCEAN_XXXXXX network used by the Homebase Station and doorbell, building on prior research into Eufy's proprietary protocols.
2026-07-29 2026PeekList: How Brave’s Playlist bypassed FaceID Protection for Private Tabs intermediate 4 min read AuthNWriteup detailing how Brave's Playlist feature on iOS bypassed Face ID/Passcode protection for Private Tabs. By adding media to a playlist and selecting "Open in a New Private Tab," users could bypass authentication, allowing unauthorized access to sensitive browsing history. Brave addressed this by integrating the `askForLocalAuthentication` prompt into the Playlist's tab opening mechanism. → infosecwriteups.com
2026-07-26 2026Android May Soon Restrict On-Device ADB news 10 min readReference on ADB security changes, this catalog entry discusses Google's potential restriction of on-device ADB connections. While intended to prevent privilege escalation exploits, specifically mentioning CVE-2026-0073's bypass, the proposed change could break legitimate workflows for developers and users of tools like Shizuku. The article highlights how on-device ADB, used via loopback connections, enables unique use cases and argues that malicious actors cannot establish such connections autonomously.
2026-07-09 20261 in 2 devices sold in Africa exfiltrate data to China news 9 min readWriteup detailing the reverse-engineering of Transsion's "Athena" and "oneID" telemetry frameworks, found on millions of TECNO, Infinix, and itel devices. The analysis reveals how embedded AES keys and a fixed IV within the client binary allow for decryption of sensitive data, including app network activity, foreground app status, precise location, and camera usage, all tied to permanent device identifiers. This research highlights significant mobile security risks stemming from hidden, first-party software collecting extensive user information without clear visibility.
2026-07-02 2026Is the Android Lock Screen an Illusion? A Critical Logical Bypass Discovered in the Gemini App intermediate 4 min read AIWriteup detailing a logical bypass vulnerability in the Gemini app on Android, discovered through a multi-touch interaction. This technique allowed unauthorized access to sensitive user data, including chat histories, NotebookLM notebooks, and Gmail drafts, by circumventing the Android Keyguard through context hijacking. The vulnerability stemmed from inadequate validation of concurrent UI interactions, creating a race condition that neutralized internal security controls. Google's VRP team confirmed and patched the issue. → infosecwriteups.com
2026-06-25 2026I Wasted 3 Days Intercepting a Flutter App. Here’s What Actually Works. intermediate BurpThe author spent three days attempting to intercept traffic from a Flutter app for a security assessment. Despite trying various methods like Objection, ReFlutter, custom CA installation, VPN interception, and Frida scripts, none were successful. The app consistently displayed a "no internet" error, rather than SSL or certificate warnings, hindering the interception process. No bounty payout amount was mentioned. → infosecwriteups.com
2026-06-12 2026Android App Penetration Testing: From APK Decompilation to Runtime Exploitation [Tools and Labs] beginnerThis article introduces the fundamentals of Android penetration testing, covering essential tools and their usage. It emphasizes the necessity of an Android virtual device or a physical device for practical application. The author, while not an expert, aims to provide a useful guide for beginners. The content highlights Android Studio as the official Integrated Development Environment (IDE) for this process. No bug bounty payout amounts are mentioned. → infosecwriteups.com
2026-06-11 2026Agentic Browser Security: 2025 Year-End Review intermediate 4 min read AISurvey of agentic browser security trends in 2025, detailing attacks like Zero-Interaction Exfiltration, Scamlexity targeting Perplexity's Comet, Gemini Trifecta, CometJacking, Tainted Memories CSRF in OpenAI Atlas, HashJack, and Task Injection in OpenAI Operator. It also covers defensive strategies emerging, including Human-in-the-Loop (HITL), Reinforcement Learning, Architectural Isolation, and Secondary LLM Critics, while noting Gartner's recommendation to block AI browser use and offering best practices for those experimenting with the technology. → wiz.io
2026-06-08 2026Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor news 18 min readLibrary for analyzing FlutterShell, a macOS backdoor deployed via Operation FlutterBridge malvertising. This payload, built with the Flutter framework, delivers adware with backdoor capabilities including shell command execution and file system manipulation. Some variants weaponize AI summarization features for data exfiltration. Operation FlutterBridge targets global audiences through Google Ads, employing shell companies to bypass vetting. The analysis details FlutterShell's WebView-based architecture, JavaScript-to-native bridge, and the challenges in dissecting Dart binaries. → unit42.paloaltonetworks.com
2026-06-08 2026A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens advanced 5 min read RCEToolchain detailing a 0-click to root exploit chain for Pixel 10, leveraging a 2026 Dolby UDC vulnerability (CVE-2025-54957) patched in early 2026, and a newly discovered VPU driver `mmap` vulnerability. The VPU bug allows arbitrary kernel read-write by mapping physical memory beyond its intended region, granting immediate kernel code execution. → projectzero.google
2026-05-22 2026Your iPhone Gets Stolen. Then the Hacking Begins beginner 5 min readAnalysis of a thriving underground ecosystem reveals how criminals are monetizing stolen iPhones by offering unlocking tools and sophisticated phishing kits, often mimicking Apple services. Researchers at Infoblox identified dozens of groups selling these services, many focusing on iPhones, and linked over 10,000 phishing websites to this activity, with traffic surging 350% last year. These illicit services commonly include tools for jailbreaking older devices, phishing kits to bypass "Find My iPhone" protections, and AI-powered voice changers for social engineering attacks, highlighting a lucrative market for stolen device access. → wired.com
2026-05-06 2026Critical Android vulnerability CVE-2026-0073 fixed by Google news 1 min read RCEReference to CVE-2026-0073, a critical remote code execution flaw in Android's System component affecting the Android Debug Bridge daemon (adbd). This vulnerability, patched by Google, allowed attackers to execute code as the shell user without privileges or user interaction. While not publicly exploited, it underscores ongoing security risks, similar to the previously exploited Qualcomm component vulnerability, CVE-2026-21385. → securityaffairs.com
2026-05-06 2026Critical Remote Code Execution Vulnerability Patched in Android news RCELibrary for patching CVE-2026-0073, a critical remote code execution flaw in the Android System component. This vulnerability in the Android Debug Bridge daemon allows exploitation without user interaction to execute code as the shell user. Google has released an update addressing this issue, noting no observed exploitation.
2026-05-05 2026Google Update: Android Flaw Could Put Billions of Devices at Risk news RCEGoogle Update: Android Flaw Could Put Billions of Devices at Risk https://ift.tt/hVIfD24 → techrepublic.com
2026-05-05 2026Android Zero-Click RCE Vulnerability Enables Remote Shell Access news 3 min read RCETool. This resource details CVE-2026-0073, a zero-click RCE vulnerability in Android's Debug Bridge daemon (adbd) affecting multiple OS versions, including Android 14-16. Exploitable from the same local network or physical proximity, it allows remote shell access without user interaction or elevated privileges, bypassing application sandboxing and potentially enabling persistence. Recommendations include timely patching, disabling USB debugging, restricting ADB access, network segmentation, and implementing zero trust policies. → esecurityplanet.com
2026-05-05 2026Google Confirms Critical Android 0-Click VulnerabilityUpdate Now news RCEGoogle Confirms Critical Android 0-Click Vulnerability—Update Now https://ift.tt/r9c8NaL
2026-05-05 2026Critical Remote Code Execution Vulnerability Patched in Android news 1 min read RCEVulnerability writeup detailing CVE-2026-0073, a critical remote code execution flaw in Android's System component affecting the Android Debug Bridge daemon ('adbd'). Exploitation allows an unauthenticated attacker to execute code as the shell user without requiring user interaction. The report notes this vulnerability has not been observed in the wild, unlike several other Android flaws from previous years such as CVE-2024-43093 and CVE‑2025‑27038. → securityweek.com
2026-05-04 2026Weekly Recap: AI-Powered Phishing Android Spying Tool Linux Exploit GitHub RCE & More news 19 min read AI RCELibrary for securing applications, this resource details ongoing threats and vulnerabilities. Key issues include active exploitation of a cPanel flaw (CVE-2026-41940) leading to authentication bypass and data wiping, and a Linux kernel vulnerability (CVE-2026-31431) enabling trivial privilege escalation. It also covers supply chain attacks via npm, PyPI, and Packagist by TeamPCP, a Python backdoor framework (DEEP#DOOR) for data theft and system manipulation, a critical GitHub flaw (CVE-2026-3854) allowing remote code execution, and the VECT 2.0 ransomware's destructive encryption method. → thehackernews.com
2026-04-29 202638 Vulnerabilities Found in OpenEMR Medical Software news 1 min read SQLiAnalysis of 38 vulnerabilities in OpenEMR, including critical SQL injection flaws (CVE-2026-24908, CVE-2026-23627) and authorization bypasses (CVE-2026-24487), reveals risks of PHI exfiltration and remote code execution. These patched issues, primarily stemming from authorization defects, were discovered by Aisle. → securityweek.com
2026-04-22 2026Root/Jailbreak Detection and SSL Pinning in KMM intermediate 8 min readLibrary implementing root/jailbreak detection and SSL pinning for Kotlin Multiplatform Mobile (KMM) applications. It details platform-specific techniques for detecting rooted Android devices by checking for the `su` binary or common root packages, and for jailbroken iOS devices by looking for Cydia or writable system directories. The library also covers SSL pinning using OkHttpClient on Android and a custom URLSessionDelegate with proxy detection on iOS to prevent man-in-the-middle attacks. The article further explores how attackers bypass these protections, particularly using Frida for dynamic instrumentation.
2026-04-22 2026Reversing Android Apps: Bypassing Detection Like a Pro intermediate 4 min readLibrary for bypassing common Android app detection mechanisms like Frida, root checks, and SSL pinning. Techniques include utilizing Magisk DenyList, employing Frida codeshare scripts, attaching Frida after app launch, static analysis with Jadx to identify and patch detection code, using Objection's `patchapk` feature, dumping loaded classes, tracing method calls, reversing native JNI code, and patching SSL pinning with `apk-mitm` for network traffic analysis.
2026-04-22 2026Reverse engineering and modifying Android apps with JADX and Frida intermediate 18 min readLibrary for reverse engineering and modifying Android applications, utilizing JADX for code extraction and Frida for dynamic instrumentation. This resource details how to decompile APKs, analyze Java source code generated by JADX, and write custom Frida scripts to bypass security measures like certificate pinning, enabling traffic interception with tools like HTTP Toolkit. It covers techniques applicable to understanding and altering app behavior beyond standard certificate pinning implementations.
2026-04-22 2026Common Vulnerabilities and Exposures Examples in Mobile Apps beginner 6 min readLibrary for validating mobile application CVEs, enabling security teams to reproduce exploits and analyze vulnerabilities in virtualized iOS and Android environments. It supports automated security assessments, real-time reporting, and tools like Frida for hooking and tracing behavior, addressing challenges posed by the rising volume of CVEs and the limitations of testing within app sandboxes. This approach moves beyond static CVE database entries to provide actionable insights into exploitable risks, exemplified by issues like CVE-2024-26131 in the Element Android App and the Operation Triangulation CVE chain impacting iOS.
2026-04-22 2026Bypassing iOS Frida Detection with LLDB and Frida intermediate 5 min readWriteup details bypassing iOS Frida detection using LLDB and Frida. The process involves jailbreaking an iPhone, setting up development tools like `libimobiledevice`, `frida-tools`, and LLDB, and then using `debugserver` for remote debugging. The author demonstrates how to find and breakpoint `FridaInTheMiddle.systemSanityCheck()` with LLDB to bypass detection, trace the `dummyFunction(flag:)` Swift function using `frida-trace` to get its mangled name, and finally hook this function with a Frida script to intercept and decode the Swift string argument, ultimately revealing the flag.
2026-04-22 2026frida-interception-and-unpinning: Scripts to MitM all HTTPS traffic intermediate 8 min readLibrary of Frida scripts automates HTTPS MitM interception on mobile devices by redirecting traffic to a proxy, injecting CA certificates into trust stores, and patching certificate pinning and transparency checks. It also handles fallback patching for obfuscated certificate pinning on Android, disables root/jailbreak detection, and blocks HTTP/3 connections. The scripts can be used independently or together to intercept HTTP(S) traffic on Android and iOS.
2026-04-22 2026Android Reports and Resources beginner 2 min readLibrary of Android security reports and resources detailing vulnerabilities such as CVE-2020-8913 in the Google Play Core library, path traversal, account takeover via deep links, sensitive information disclosure, arbitrary code execution in TikTok, memory corruption exploitation, SQL injection in Content Providers, and XSS via WebView. It includes resources on secure cryptography, WebResourceResponse configurations, and vendor-specific issues in Xiaomi and Samsung devices, alongside references to vulnerable Android applications like Oversecured, GoatDroid, and Sieve for educational purposes.
Browse all 156 Mobile Security resources →

Frequently Asked Questions

What is the OWASP Mobile Top 10?
The OWASP Mobile Top 10 covers the most critical mobile application security risks: Improper Credential Usage, Inadequate Supply Chain Security, Insecure Authentication/Authorization, Insufficient Input/Output Validation, Insecure Communication, Inadequate Privacy Controls, Insufficient Binary Protections, Security Misconfiguration, Insecure Data Storage, and Insufficient Cryptography.
What tools are used for mobile app security testing?
Essential tools include Frida and objection for dynamic instrumentation, MobSF for automated static and dynamic analysis, Jadx and apktool for Android reverse engineering, Hopper and Ghidra for iOS binary analysis, and proxy tools like Burp Suite or mitmproxy for intercepting API traffic with certificate pinning bypass.
How is mobile security testing different from web testing?
Mobile testing adds client-side concerns: local data storage, binary protections, certificate pinning, inter-app communication, and platform-specific features. You must analyze the compiled binary, not just network traffic. Reverse engineering reveals hardcoded secrets, hidden endpoints, and client-side logic that attackers can manipulate.

Weekly AppSec Digest

Get new resources delivered every Monday.