Safeguard
Tag

mobile-security

Safeguard articles tagged "mobile-security" — guides, analysis, and best practices for software supply chain and application security.

47 articles

Application Security

Your API Returns More Than Your Interface Shows

The interface filters. The API does not. Serialising a model directly makes your API contract your database schema, so a column added for an internal feature is exposed the moment it is added.

Sep 18, 20265 min read
Application Security

Your Old API Version Is Still Serving and It Did Not Get the Fix

You shipped v2 with a tightened authorisation check. v1 is still live because nobody knows who calls it. An attacker does not have to use v2.

Sep 18, 20265 min read
Application Security

A Deep Link Is an Unauthenticated Entry Point Into Your App

Anything can send one: a web page, a QR code, a message, another app on the device. With a custom scheme there is not even a guarantee the link reaches your app rather than someone else's.

Sep 18, 20265 min read
Application Security

You Cannot Patch a Mobile App Quickly, So Build the Kill Switch First

Server-side remediation is a deployment. Mobile remediation is a distribution problem with a tail you do not control, and a share of your install base will still be running the vulnerable version next year.

Sep 18, 20266 min read
Vulnerability Analysis

Samsung's Year: A Signage Server Bug and a Codec Library Hit Twice for Spyware

Three confirmed-exploited Samsung vulnerabilities span an enterprise digital signage server and a mobile image codec library hit twice in five months, one tied to commercial-grade Android spyware.

Sep 16, 20265 min read
Vulnerability Analysis

Android Framework and Qualcomm Chipsets: Four CVEs Across the Mobile Stack

Three Android Framework privilege-escalation bugs and a Qualcomm chipset memory corruption flaw, confirmed exploited across the software and silicon layers of the Android ecosystem.

Sep 16, 20265 min read
Open Source

react-native-confirmation-code-field: Building Secure OTP Input

This tiny React Native library gives you a clean OTP entry UI, but a secure one-time-code flow is mostly about what happens around the field, not in it.

Jul 17, 20266 min read
Open Source Security

Mobile app dependency vulnerability trends

Mobile apps now ship more third-party code than first-party. Safeguard's analysis breaks down where dependency vulnerabilities cluster and why.

Jul 14, 20267 min read
Buyer's Guides

Best software composition analysis tools for mobile appli...

A no-hype comparison of mobile SCA tools for scanning iOS and Android dependencies, generating SBOMs, and catching open-source vulnerabilities before release.

Jul 13, 20267 min read
Open Source

@twotalltotems/react-native-otp-input: A Security Guide

This popular OTP input component for React Native has not shipped an update in years. Here is a security guide to using @twotalltotems/react-native-otp-input, or moving off it.

Jul 9, 20265 min read
Application Security

Implementing SSL/TLS certificate pinning in Node.js

HTTP Public Key Pinning died in Chrome 67 back in 2018, yet Node.js apps still need pinning for mobile backends and server-to-server calls — here's how to do it without bricking your own API.

Jul 8, 20266 min read
Security Guides

Dart and Flutter Security Best Practices: Storage, Transport, and the pub.dev Supply Chain

A Flutter binary ships to both stores from one codebase — including any hardcoded secret, any disabled TLS check, and any vulnerable pub.dev package. Here is how to close each gap.

Jul 7, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.