Resources

Guides, research and release notes

Practical writing on mobile application security — OWASP MASVS in practice, reverse-engineering technique, and what we learn from the apps we scan.

28 September 2026

26,686 trips, no login required

A ride-sharing app shipped a Supabase anon key and left Row Level Security off one table. 26,686 trip records were readable by anyone who installed the app.

mobile-securitysupabaserow-level-securitydata-exposure
28 September 2026

Encrypted on the App Store, readable in a terminal

App Store encryption protects the Mach-O executable, not the React Native bundle beside it. Hermes bytecode isn't encryption either, and every string the app was compiled with is still in there.

mobile-securityreact-nativestatic-analysis

See what your own app is leaking

Scan an APK or IPA and get findings mapped to OWASP MASVS, with code-level remediation.

Start a free scan