Neutron, our AI engine, scored 96.75% on UC Berkeley's CyberGym benchmark. Learn more

Tag

#Android

34 articles

Detection and enforcement are different security properties. Across five production banking apps protected by four commercial shielding products, the detection was sophisticated and the enforcement was fragile.

Security

BeatBanker/BTMOB Android Banking Malware Analysis

Static analysis of TV_V_23.apk, BeatBanker/BTMOB Android banking malware disguised as a flashligh...

Apr 28, 2026

Security

Android Intent Redirection: Attacks and Fixes

How intent redirection lets attackers reach unexported Android components, leak data via setResul...

Apr 23, 2026

Security

Android Developer Verification 2026: Who Needs It

From 2026, certified Android devices can block apps from unverified developers. What changes for ...

Jan 27, 2026

More tagged #Android

Android WebView addJavascriptInterface Risks

Case study: Ostorlab's AI pentest engine finds an Android WebView JavaScript bridge reachable via deep links and chains it into native UI manipulation.

Jan 07, 2026

Best Mobile App Security Testing Platforms 2026

Compare Ostorlab, NowSecure, Appknox, Data Theorem, Quokka, Zimperium and MobSF for Android and iOS, with a feature matrix and vendor proof-of-value questions.

Jan 05, 2026

Android FLAG_SECURE: Block Screenshots and Recording

How Android's FLAG_SECURE blocks screenshots, screen recording and recent-apps previews, with code samples, use cases, limitations and casting behavior.

Dec 29, 2025

Going Beyond: Ostorlab AI Engine Discovers Unknown Vulnerability Classes

Ostorlab’s reasoning-driven AI engine breaks past rule-based limits to surface previously unknown and hard-to-detect vulnerabilities—including WebView Safe Browsing bypasses, SQLi via projections, WebCrypto key exfiltration, and JWT verification ordering flaws—delivering deeper, smarter, complementary security coverage.

Oct 13, 2025

Introducing Ostorlab Security Testing Benchmarks: Real Vulnerabilities, Real Impact

The first open-source benchmark suite featuring 93 realistic vulnerable mobile apps that mirror actual CVE and bug bounty findings - not theoretical textbook examples.

Sep 22, 2025

AI-Powered Pentesting: A Deep Dive into Android Intent Redirection

This article showcases Ostorlab's AI Pentest Engine's process for analyzing an Android application for Intent Redirection vulnerabilities. Follow the engine's journey from static analysis and initial findings to rigorous dynamic validation, demonstrating its ability to not only identify potential threats but also to meticulously discard false positives.

Aug 31, 2025

Know Your App's Data Habits: A Deep Dive into Our Comprehensive Privacy Analysis

Ostorlab's Privacy Scan automatically detects mismatches between what your app's privacy policy says and what it actually does. This comprehensive analysis of policy text, permissions, code, and UI elements helps mobile developers avoid compliance violations and build user trust through accurate privacy practices.

May 27, 2025

Secure Biometric Login in Kotlin, Swift and Flutter

In this Article, we define a secure implementation of mobile biometric authentication and provide detailed implementations in the 3 main modern mobile languages, namely Kotlin for Android, Swift for iOS, and Dart for Flutter multiplatform applications.

Jun 20, 2023

GodFather Android Malware Analysis

In This article, we analyze the GodFather Android malware, which continues to appear in various formats and primarily targets banking and cryptocurrency applications to steal money and sensitive information for the users.

Apr 14, 2023

Mobile CI/CD with Jenkins, GitHub Actions, Azure DevOps

This article will cover the main challenges when implementing a CI/CD pipeline for mobile applications. We will also provide examples of how you can implement a CI/CD pipeline for Android and iOS applications in the most used Mobile CI/CD tools.

Oct 27, 2022


Previous
1 of 3