Sony Pixel Power calrec Sony

HP Research Reveals Nine out of 0 Mobile Applications Vulnerable to Attack

18/11/2013

HP Research Reveals Nine out of 10 Mobile Applications Vulnerable to Attack

NEW YORK - HP today released results from a research study revealing that mobile applications represent a real security threat, with vulnerabilities affecting nine out of 10 mobile applications published by a representative sample of companies on the Forbes Global 2000.

According to the study, 97 percent of the mobile applications tested accessed at least one private information source within a device, and 86 percent of those applications did not have adequate security measures in place to protect them from the most common exploits.

As computing becomes borderless, adversaries are increasingly bypassing perimeter security with ease and taking advantage of vulnerabilities brought on by the growing number of applications and entry points. According to Gartner, Inc., mobile app stores will see annual downloads reach 102 billion in 2013, up from 64 billion in 2012.(1) This spike in demand is pushing business managers to dramatically increase the speed at which they deploy mobile applications, and driving more of the development to third parties. This results in less oversight of security, and emphasizes the need for a mobile security strategy that enables businesses to go from fast to market to secure and fast to market.

While mobile devices are becoming more and more critical to conducting business, they are also becoming prime targets for attack, with vulnerable applications providing access to sensitive data, said Mike Armistead, vice president and general manager, Enterprise Security Products, Fortify, HP. Mobile applications now are the first line of defense against the adversary and organizations must be equipped to assess, assure and protect these applications to prevent damage from exploits.

Sensitive corporate data and personal information are often housed side by side on insecure devices. This introduces unnecessary vulnerabilities that can be easily resolved if they are identified and addressed. The HP research study leveraged HP Fortify on Demand to scan more than 2,100 mobile applications from more than 600 companies, revealing alarming realities regarding the sheer number of applications vulnerable to attack.

The most common and easily addressable vulnerability sources reported include:

Privacy issues: Of 2,107 mobile applications scanned, 97 percent accessed private data sources including personal address books, social media pages and connectivity options like Bluetooth or Wi-Fi. Of those applications, 86 percent did not have adequate security measures in place to protect them from the most common exploits, such as misuse of unencrypted data, cross-site scripting and insecure transmission of data.

Lack of binary protections: 86 percent of applications tested lacked binary hardening, leaving applications vulnerable to information disclosure, buffer overflows and poor performance. To ensure security throughout the life cycle of the application, it is essential to build in the best security practices from conception.

Insecure data storage: 75 percent of applications did not use proper encryption techniques when storing data on mobile devices, which leaves unencrypted data accessible to an attacker. This data includes passwords, personal information, session tokens, documents, chat logs and photos. Unencrypted data that is seen and used by a malicious attacker can violate numerous corporate governance policies as well as compromise the reputation of the enterprise if sensitive trade secrets are leaked to competitors, the media or any other variety of recipients with negative consequences.

Transport security: 18 percent of applications tested sent user names and passwords over HTTP. Of the remaining 82 percent, 18 percent incorrectly implemented SSL/HTTPS. These unprotected credentials are typically used not only for the mobile applications but also by their web application counterparts. This further compounds the issue, since malicious attackers on the same network could then sniff that data.

Laying the groundwork for a basic mobile application security strategy allows organizations to identify vulnerabilities before they are exploited. Nearly all vulnerabilities can be found and remediated by simply running a security assessment test before releasing or procuring a mobile application. This can identify the most common vulnerabilities and assess whether data is being passed maliciously or stored insecurely. HP Fortify on Demand for Mobile enables organizations to assess vulnerabilities across mobile applications, assure security flaws are resolved before deployment, and protect applications from attacks once in production.

Software development is not a perfect science-but it was imperative that we had a robust security assurance process in place to protect our credit union members, said Atul Varde, SVP and CIO, Affinity Credit Union. With emerging technologies such as mobile applications, where things are changing at a very rapid pace, the sort of independent experience and oversight that HP Fortify on Demand provides makes the whole process more secure.

Methodology

Conducted by HP Security Research (HPSR), the mobile application security study tested the security posture of 2,107 applications published by 601 companies on the Forbes Global 2000. The companies represented 50 countries across 76 industries. Applications were selected from 22 categories such as productivity and social networking, and were tested using the HP Fortify on Demand automated binary and dynamic analysis engine. Application testing was conducted during October and November 2013.

Additional information about mobile application security and further details resulting from the study are available at www.hp.com/go/fortifymobile.

(1) Gartner Press Release; Gartner Says Mobile App Stores Will See Annual Download
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=1528865...
See more stories from hp

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

04/08/2026

Dalet Announces Commercial Availability of Dalia, Bringing Media-Aware Agentic AI to Enterprise Productions

Dalet, a leading technology and service provider for media-rich organizations, t...

04/07/2026

Detective Conan: Fallen Angel of the Highway Opens in Dolby Cinemas Across Japan, Presented in Dolby Atmos and Dolby ...

April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

23/05/2026

FOX Sports, IMS Productions Scale Up Indy 500 Production With New In-Car Cameras, AR Graphics, Cinematic Sets

In its second year as rightsholder, FOX Sports goes bigger across the board for ...

23/05/2026

Inside Apple TVs MLS iPhone Production with Royce Dickerson, Apple Live Sports, Executive Producer

Tonight's MLS matchup between the LA Galaxy and the Houston Dynamo FC will m...

23/05/2026

IK Multimedia reveal ReSing Voices Japanese Pack

AI-powered vocal tool gains first new language expansion IK Multimedia's AI-powered voice-creation software has seen a number of updates since it launch...

23/05/2026

Building a better future: Nielsen celebrates Global Volunteer Month and Earth Day 2026 with record participation

Nielsen Global Leadership Network graduates celebrate Earth Day 2026 Nielsen vo...

23/05/2026

Gray Media Names New Station General Managers

Share Copy link Facebook X Linkedin Bluesky Email...

23/05/2026

New CIMM Paper Urges Industry to Rethink How Media Is Evaluated

Share Copy link Facebook X Linkedin Bluesky Email...

23/05/2026

Lawo to Showcase Edge One, Efficient IP Workflows at InfoComm 2026

Share Copy link Facebook X Linkedin Bluesky Email...

23/05/2026

Spectrum Launches Ultra-Low Latency Internet

Share Copy link Facebook X Linkedin Bluesky Email...

22/05/2026

Germanys Magenta TV Selects DMC to Provide FIFA World Cup Technical Support for Studios in Munich, New York City

Germany's Magenta TV, which will have 44 exclusive FIFA World Cup match broa...

22/05/2026

DAZN Grabs IFAF Flag Football Global Rights

DAZN, the world's leading sports entertainment platform, has acquired global broadcast rights to the International Federation of American Football's ( I...

22/05/2026

ATHLOS 2026 Season Set for October Debut in London; Aurora Media Worldwide Named Host Broadcast Partner

ATHLOS, the all-women's professional track and field league, has announced i...

22/05/2026

NATAS to Stream Sports, News, and Documentary Emmy Awards Live on YouTube

The National Academy of Television Arts & Sciences (NATAS) today announced that the 47th Annual Sports Emmy Awards and the 47th Annual News & Documentary Emmy A...

22/05/2026

Wooden Camera Rolls Out New Blackmagic URSA Accessories

Wooden Camera today announced the release of new accessories for the Blackmagic URSA Cine Immersive. The new lineup includes a redesigned Top Plate and Side Rai...

22/05/2026

YES Network, OTT Advisors Extend Streaming Partnership for Sixth Season

YES Network and OTT Advisors have announced a sixth consecutive season of their streaming partnership, continuing their collaboration on the Gotham app. OTT Adv...

22/05/2026

NESN Monster Week' Returns With Full Red Sox Broadcast From Atop Green Monster

NESN, New England's premier sports network, will again turn its camera to Fe...

22/05/2026

Dale Pro Audio RF Over Fiber Webinar Set for May 28

Dale Pro Audio is hosting an RF over Fiber Livestream Webinar on May 28 from 1-2:30 pm EST. With major sporting events and large-scale productions putting incre...

22/05/2026

Audio-Technica Appoints Humrichouser, Schanz to New Roles

Audio-Technica has announced key leadership appointments designed to further strengthen its sales organization and drive continued growth across the Americas. M...

22/05/2026

Scott Coker Launches Global MMA League With $60 Million in Backing

After nearly four decades shaping the global combat sports landscape, Scott Coker has announced a powerful return as he looks to build a new international mixed...

22/05/2026

Skyline Launches xOps Vanguard Runway for Autonomous Era

Skyline Communications, the company behind the globally deployed DataMiner xOps platform, today announced the launch of xOps Vanguard Runway, a strategic accele...

22/05/2026

The American Rodeo Takes Over Globe Life Field for Championship Weekend

For the fully onsite production, 30 cameras - including a SkyCam and Megalodon - will capture the action in Texas One of the world's biggest rodeo producti...

22/05/2026

Argentinas Torneos Taps Imagine Versio for Playout Operations Upgrade

Leading Argentina-based sports media company Torneos y Competencias S.A. has modernized its playout operations, implementing a fully redundant, multichannel env...

22/05/2026

Owl AI and Major League Pickleball Go Live with First-Ever AI Officiating System Powered by Broadcast Cameras and the Cloud

As the 2026 Major League Pickleball season kicks off this weekend in Dallas, it ...

22/05/2026

Shure, Edge Sound Research Look to Innovate via Partnership

Shure has become a minority investor in Edge Sound Research, a start-up company that is developing new experiential audio technologies that redefine how many au...

22/05/2026

SVG Rewind: MLBs UmpCam AR System Puts Fans Inside the Strike Zone Like Never Before

In advance of this year's Sports Emmy Awards, SVG is taking a deep dive into...

22/05/2026

Jelly Roll Offers Up 2026 Stanley Cup Playoff Theme Song for NHL, Amazon Music

The National Hockey League (NHL) and Amazon Music announced that GRAMMY Award-winning superstar Jelly Roll will provide the official theme song of the 2026 Stan...

22/05/2026

David Pogue, Andy Beach Keynotes Highlight Silicon Valley Video Summer Camp, July 14 at De Anza College

David Pogue will keynote SVV Summer Camp and discuss Apple at 50: How the World...

22/05/2026

FOX Sports, IMS Productions Scale Up Indy 500 Production in Year Two With New In-Car Cameras, AR Graphics, and Cinematic Sets

In its second year as rightsholder, FOX Sports goes bigger across the board for ...

22/05/2026

FOX Sports' Indy 500 Director Mitch Riggin on the Tech and Storytelling for the Greatest Spectacle in Racing

The broadcaster is drawing on lessons learned in its first year of covering the ...

22/05/2026

How Spotify's Rebuilt Ad Platform Is Delivering New Value for Brands

At our 2026 Investor Day, we shared an inside look at the rebuild of our advertising business. This pivot to our own purpose-built platform is already driving s...

22/05/2026

Spotify Levels Up Our Podcast Experience With New Features for Fans and Creators

Podcasting on Spotify continues to grow, and so do the ways listeners engage with it. At Investor Day 2026, we shared how we're building the next chapter of...

22/05/2026

CEDAR Audio introduce Icons Bundles

Limited-time collections now available Restoration experts CEDAR Audio have recently launched a new line of Icons plug-ins that make their powerful processo...

22/05/2026

Boss expand PS-1 Plugout Pedal

Three new classics join Model Pass line-up Boss' PX-1 Plugout Pedal offers an innovative approach to guitar pedals, providing users with a hardware stom...

22/05/2026

SGL Carbon commissions photovoltaic system and lays the foundation for a new nitrogen plant at its Meitingen site

At its Meitingen site, SGL Carbon has implemented two key projects to further de...

22/05/2026

Statement regarding 2026 National NAIDOC Lifetime Achievement Award for the late Rhoda Roberts AO

Statement regarding 2026 National NAIDOC Lifetime Achievement Award for the late...

22/05/2026

Polsat Reclaims Second Place and ByteDance Enters Top 10 as Polish Viewing Moves Beyond the Living Room in April

Latest data reveals steady distributor rankings, a seasonal shift toward digital...

22/05/2026

FCC Votes to Update Disaster Information Reporting System

Share Copy link Facebook X Linkedin Bluesky Email...

22/05/2026

Amagi delivers 30 per cent revenue growth in FY26 Adjuste...

Amagi Media Labs Limited (NSE: AMAGI, BSE: 544679), a cloud-native SaaS platform providing AI-enabled solutions to global media and entertainment companies, tod...

22/05/2026

Annima Post Relies on Cintel to Revive Classic Mexican Films

An nima Post Relies on Cintel to Revive Classic Mexican Films Brie Clayton May 22, 2026 0 Comments Film scanner and DaVinci Resolve Studio help manage...

22/05/2026

Boris FX Sapphire Adds Optical Beauty and Hypnotic Textures

Boris FX Sapphire Adds Optical Beauty and Hypnotic Textures Jessie Electa Petrov May 22, 2026 0 Comments The 2026.5 release introduces advanced defocu...

22/05/2026

Deployment Preserves Trusted Workflows While Enabling a P...

Deployment Preserves Trusted Workflows While Enabling a Path to UHD and SMPTE ST 2110 Leading Argentina-based sports media company Torneos y Competencias S.A....

22/05/2026

Study: AI Labeling Does Not Hurt Video Ad Performance

Share Copy link Facebook X Linkedin Bluesky Email...

22/05/2026

NAB Show Makes 200+ Sessions Available on Demand

Share Copy link Facebook X Linkedin Bluesky Email...

22/05/2026

Torneos Upgrades Multichannel Playout with Imagine's Versio

Share Copy link Facebook X Linkedin Bluesky Email...

22/05/2026

Ex-Husband, Current Husband, One Wild Rescue: Korean Action Comedy Husbands in Action' Premieres June 19

Back to All News Ex-Husband, Current Husband, One Wild Rescue: Korean Action Co...

22/05/2026

Beta Da Silva hosts live performances from 20 new Irish artists in Sessions from Oblivion on 2FM's New Music Show

Catch the latest in Irish music live from venues such as Whelan's, R is n Du...

21/05/2026

CBS Sports Expands WNBA Tip-Off Show To Cover Half of 20-Game, Regular-Season Package

Game Creek Video Columbia and Celtic, NEP Supershooter 8 will house onsite produ...