mobile-security
Safeguard articles tagged "mobile-security" — guides, analysis, and best practices for software supply chain and application security.
47 articles
Your API Returns More Than Your Interface Shows
The interface filters. The API does not. Serialising a model directly makes your API contract your database schema, so a column added for an internal feature is exposed the moment it is added.
Your Old API Version Is Still Serving and It Did Not Get the Fix
You shipped v2 with a tightened authorisation check. v1 is still live because nobody knows who calls it. An attacker does not have to use v2.
A Deep Link Is an Unauthenticated Entry Point Into Your App
Anything can send one: a web page, a QR code, a message, another app on the device. With a custom scheme there is not even a guarantee the link reaches your app rather than someone else's.
You Cannot Patch a Mobile App Quickly, So Build the Kill Switch First
Server-side remediation is a deployment. Mobile remediation is a distribution problem with a tail you do not control, and a share of your install base will still be running the vulnerable version next year.
Samsung's Year: A Signage Server Bug and a Codec Library Hit Twice for Spyware
Three confirmed-exploited Samsung vulnerabilities span an enterprise digital signage server and a mobile image codec library hit twice in five months, one tied to commercial-grade Android spyware.
Android Framework and Qualcomm Chipsets: Four CVEs Across the Mobile Stack
Three Android Framework privilege-escalation bugs and a Qualcomm chipset memory corruption flaw, confirmed exploited across the software and silicon layers of the Android ecosystem.
react-native-confirmation-code-field: Building Secure OTP Input
This tiny React Native library gives you a clean OTP entry UI, but a secure one-time-code flow is mostly about what happens around the field, not in it.
Mobile app dependency vulnerability trends
Mobile apps now ship more third-party code than first-party. Safeguard's analysis breaks down where dependency vulnerabilities cluster and why.
Best software composition analysis tools for mobile appli...
A no-hype comparison of mobile SCA tools for scanning iOS and Android dependencies, generating SBOMs, and catching open-source vulnerabilities before release.
@twotalltotems/react-native-otp-input: A Security Guide
This popular OTP input component for React Native has not shipped an update in years. Here is a security guide to using @twotalltotems/react-native-otp-input, or moving off it.
Implementing SSL/TLS certificate pinning in Node.js
HTTP Public Key Pinning died in Chrome 67 back in 2018, yet Node.js apps still need pinning for mobile backends and server-to-server calls — here's how to do it without bricking your own API.
Dart and Flutter Security Best Practices: Storage, Transport, and the pub.dev Supply Chain
A Flutter binary ships to both stores from one codebase — including any hardcoded secret, any disabled TLS check, and any vulnerable pub.dev package. Here is how to close each gap.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.