OWASP
OWASP Mobile Top 10
The ten most critical mobile application security risks, published by OWASP and refreshed for 2024. Strata maps every applicable finding to one of these ten categories on every Android and iOS scan.
Entries
OWASP Mobile Top 10 Reference Entries
4 of 4 entries
OWASP M10
M1M1: Improper Credential Usage
Hardcoded secrets, API keys, and tokens embedded directly in an application binary or source, rather than provisioned at runtime.
OWASP M10
M2M2: Inadequate Supply Chain Security
Third-party dependencies and SDKs with known vulnerabilities, malicious packages, or outdated components pulled directly into the app.
OWASP M10
M5M5: Insecure Communication
Cleartext traffic, weak TLS configuration, or disabled certificate pinning that exposes data while it moves between the app and its backend.
OWASP M10
M9M9: Insecure Data Storage
Sensitive data persisted in plaintext — SharedPreferences, SQLite, external storage, or an unprotected Keychain entry.