Resources
Guides, research and release notes
Practical writing on mobile application security — OWASP MASVS in practice,
reverse-engineering technique, and what we learn from the apps we scan.
28 September 2026
A ride-sharing app shipped a Supabase anon key and left Row Level Security off one table. 26,686 trip records were readable by anyone who installed the app.
mobile-securitysupabaserow-level-securitydata-exposure
28 September 2026
App Store encryption protects the Mach-O executable, not the React Native bundle beside it. Hermes bytecode isn't encryption either, and every string the app was compiled with is still in there.
mobile-securityreact-nativestatic-analysis
28 September 2026
One scan produced 116 findings. Eight rows described a single missing capability, and 93 of them landed in the tier everyone skips.
mobile-securitytriagefalse-positives