Watch out, your work mobile apps could be a huge security risk - here's what to look out for

Most enterprise mobile apps carry some vulnerabilities which can be used to grab sensitive data.

Apr 17, 2025 - 16:09
 0
Watch out, your work mobile apps could be a huge security risk - here's what to look out for

  • Almost all enterprise mobile apps come with security risks, experts warn
  • Most frequent flaws include misconfigured cloud storage, hardcoded credentials, or outdated cryptography
  • Zimperium shares its advice on how to stay safe

If your business is using mobile apps, there is a good chance those apps are leaking sensitive information and putting your entire operation at risk of data breaches, loss of trust, regulatory fines, and a whole swathe of other headaches.

Cybersecurity researchers Zimperium analyzed more than 17,000 enterprise mobile apps, and revealed many carry vulnerabilities such as misconfigured cloud storage, hardcoded credentials, or outdated cryptography, and while these are not tied to a particular platform, there were significantly more iOS apps vulnerable (11,626 on iOS compared to 6037 on Android).

Breaking the numbers down, the researchers found 83 Android apps with misconfigured or otherwise unprotected cloud storage, and 10 Android apps with exposed AWS credentials.

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)View Deal

Spoofing SharePoint

Almost all of the analyzed apps used weak or flawed cryptography, and five of the top 100 apps had high-severity cryptographic flaws. Others, also from the top 100, had storage directories exposed to the public.

“Our research found that 88% of all apps and 43% of the top 100 use one or more cryptographic methods that don't follow best practices,” the researchers said. “In some cases - high-severity cryptography flaws.”

To avoid these risks, Zimperium suggests that every company’s mobile device fleet manager gains visibility into app behavior patterns. That way, they’ll be able to identify misconfigured cloud storage settings, detect exposed credentials and API keys, and evaluate cloud service integration security.

Furthermore, they should validate encryption methods and key management, identify outdated or weak algorithms, assess security of integrated cloud SDKs, validate third-party cryptographic implementations, and monitor for known vulnerabilities.

“We cannot change the apps, but we can choose which apps we allow to ensure our data’s security,” they concluded.

You might also like