
HP Research Reveals Nine out of 10 Mobile Applications Vulnerable to Attack
NEW YORK - HP today released results from a research study revealing that mobile applications represent a real security threat, with vulnerabilities affecting nine out of 10 mobile applications published by a representative sample of companies on the Forbes Global 2000.
According to the study, 97 percent of the mobile applications tested accessed at least one private information source within a device, and 86 percent of those applications did not have adequate security measures in place to protect them from the most common exploits.
As computing becomes borderless, adversaries are increasingly bypassing perimeter security with ease and taking advantage of vulnerabilities brought on by the growing number of applications and entry points. According to Gartner, Inc., mobile app stores will see annual downloads reach 102 billion in 2013, up from 64 billion in 2012.(1) This spike in demand is pushing business managers to dramatically increase the speed at which they deploy mobile applications, and driving more of the development to third parties. This results in less oversight of security, and emphasizes the need for a mobile security strategy that enables businesses to go from fast to market to secure and fast to market.
While mobile devices are becoming more and more critical to conducting business, they are also becoming prime targets for attack, with vulnerable applications providing access to sensitive data, said Mike Armistead, vice president and general manager, Enterprise Security Products, Fortify, HP. Mobile applications now are the first line of defense against the adversary and organizations must be equipped to assess, assure and protect these applications to prevent damage from exploits.
Sensitive corporate data and personal information are often housed side by side on insecure devices. This introduces unnecessary vulnerabilities that can be easily resolved if they are identified and addressed. The HP research study leveraged HP Fortify on Demand to scan more than 2,100 mobile applications from more than 600 companies, revealing alarming realities regarding the sheer number of applications vulnerable to attack.
The most common and easily addressable vulnerability sources reported include:
Privacy issues: Of 2,107 mobile applications scanned, 97 percent accessed private data sources including personal address books, social media pages and connectivity options like Bluetooth or Wi-Fi. Of those applications, 86 percent did not have adequate security measures in place to protect them from the most common exploits, such as misuse of unencrypted data, cross-site scripting and insecure transmission of data.
Lack of binary protections: 86 percent of applications tested lacked binary hardening, leaving applications vulnerable to information disclosure, buffer overflows and poor performance. To ensure security throughout the life cycle of the application, it is essential to build in the best security practices from conception.
Insecure data storage: 75 percent of applications did not use proper encryption techniques when storing data on mobile devices, which leaves unencrypted data accessible to an attacker. This data includes passwords, personal information, session tokens, documents, chat logs and photos. Unencrypted data that is seen and used by a malicious attacker can violate numerous corporate governance policies as well as compromise the reputation of the enterprise if sensitive trade secrets are leaked to competitors, the media or any other variety of recipients with negative consequences.
Transport security: 18 percent of applications tested sent user names and passwords over HTTP. Of the remaining 82 percent, 18 percent incorrectly implemented SSL/HTTPS. These unprotected credentials are typically used not only for the mobile applications but also by their web application counterparts. This further compounds the issue, since malicious attackers on the same network could then sniff that data.
Laying the groundwork for a basic mobile application security strategy allows organizations to identify vulnerabilities before they are exploited. Nearly all vulnerabilities can be found and remediated by simply running a security assessment test before releasing or procuring a mobile application. This can identify the most common vulnerabilities and assess whether data is being passed maliciously or stored insecurely. HP Fortify on Demand for Mobile enables organizations to assess vulnerabilities across mobile applications, assure security flaws are resolved before deployment, and protect applications from attacks once in production.
Software development is not a perfect science-but it was imperative that we had a robust security assurance process in place to protect our credit union members, said Atul Varde, SVP and CIO, Affinity Credit Union. With emerging technologies such as mobile applications, where things are changing at a very rapid pace, the sort of independent experience and oversight that HP Fortify on Demand provides makes the whole process more secure.
Methodology
Conducted by HP Security Research (HPSR), the mobile application security study tested the security posture of 2,107 applications published by 601 companies on the Forbes Global 2000. The companies represented 50 countries across 76 industries. Applications were selected from 22 categories such as productivity and social networking, and were tested using the HP Fortify on Demand automated binary and dynamic analysis engine. Application testing was conducted during October and November 2013.
Additional information about mobile application security and further details resulting from the study are available at www.hp.com/go/fortifymobile.
(1) Gartner Press Release; Gartner Says Mobile App Stores Will See Annual Download
Most recent headlines
09/11/2025
Dalet today announced a transformative leap forward for media operations: Agentic Artificial Intelligence (AI) that unifies the Dalet ecosystem under one natura...
03/11/2025
In less than two weeks during late September and early October, the Federal Communications Commission acted on two proposed rulemakings that could have an enorm...
03/11/2025
Josh Miely is returning to a more hands-on radio and TV role with the National Association of Broadcasters....
03/11/2025
Broadcasters have spent years trying to integrate different vendor technologies in their facilities. As the industry has moved closer to software, that struggle...
03/11/2025
As the malevolent siege against broadcasters' interests intensifies from the far reaches of artificial intelligence misuse to relentless innovation in the m...
03/11/2025
Wheatstone founder and owner Gary Snow will retire from the company by the end of next year....
03/11/2025
In ye olde days of traditional television, when U.S. TV viewing options were limited to ABC, CBS, NBC and PBS, Nielsen's paper diaries were sufficient for t...
03/11/2025
They've made that decision and ruined an awful lot of people's lives.
...
02/11/2025
Abu Dhabi, UAE November 2, 2025: Space42 (ADX: SPACE42), the UAE-based AI-powe...
01/11/2025
Thunderbolt 3 Now Standard on Symphony MkII - Starting November 11 Beginning November 11, all new Apogee Symphony I/O MkII units will ship with Thunderbolt 3 as...
01/11/2025
How to Expand the Apogee Symphony Desktop with Cranborne 500ADAT Want to expand your Symphony Desktop beyond two inputs? Whether you're tracking a full drum...
01/11/2025
aconnic AG (ISIN: DE000A0LBKW6), Munich, has published the Financial Report for ...
01/11/2025
tvONE is proud to announce a strategic partnership with Matrox Video, combining CALICO PRO's high-performance video processing with the Matrox ConvertIP Ser...
01/11/2025
CJP Broadcast has joined the Grass Valley partner programme as both a Systems Integration Partner and AMPP Partner. The collaboration enhances CJP's ability...
01/11/2025
TAG Video Systems, the leader in software-based IP end-to-end workflow monitoring, deep probing, and real-time visualization, has earned a higher-rated DPP Comm...
01/11/2025
Michael Napodano Appointed New CEO Of Operative Media
Operative today announced the appointment of Mike Napodano as Chief Executive Officer, marking the next s...
01/11/2025
Film industry professionals flocked to Cine Gear Expo Atlanta 2025 at celebrated Trilith Studios in Fayetteville, Georgia, on October 3 and 4. Back for its 6th ...
01/11/2025
Photo courtesy of Peacock and Sky
Christopher Ross, BSC, began his cinematic obsession early. He cites reading Scorsese on Scorsese as a teenager with teaching...
01/11/2025
NEW YORK ITN and the sell-side advertising company Magnite have announced the launch of what they are billing as the industrys first Local Linear TV Private Mar...
31/10/2025
FanDuel Sports Network To Deliver Selected Live NBA, NHL Games to Major Streamin...
31/10/2025
NBC Jumps Out of the Gate in Extended Breeder's Cup Deal With Dual Drones, J...
31/10/2025
FOR IMMEDIATE RELEASE
30 October 2025
It is with great sadness that we mourn the passing of Segomotso Keorapetse, an award- winning South African television d...
31/10/2025
IRVING, Texas As station groups move into an era that promises rapid tech, regulatory and economic changes, Nexstar Media Group said its board has extended chai...
31/10/2025
While some analysts have questioned the ongoing economic viability of broacast-TV late night shows amid ongoing declines in linear viewing, new data from Tubula...
31/10/2025
The contentious contract negotiations between The Walt Disney Co. and YouTube TV have resulted in a blackout of Disney-owned programming on the pay TV operator....
31/10/2025
CINCINNATI Video conversion and AV signal distribution specialist tvONE and Matrox Video have struck a strategic partnership, combining CALICO PRO's video p...
31/10/2025
NEW YORK The Interactive Advertising Bureau (IAB) today released a new industry guide that discusses the urgency of adopting new standards that will help advert...
31/10/2025
While some analysts have questioned the ongoing economic viability of late night shows on broadcast TV amid ongoing declines in linear viewing, new data from Tu...
31/10/2025
Berklee Celebrates the Inauguration of President Jim Lucchese In his inaugural address, Lucchese shared an optimistic vision for Berklee's future as a for...
31/10/2025
Back to All News
Family, Food, and Films: Netflix's Dining with the Kapoors...
31/10/2025
The review highlights DPA 4055 Kick Drum Microphone for its compact design, ease of placement, and authentic tone that captures the true character of the drum p...
31/10/2025
The RT Raidi na Gaeltachta Award 2025 will be presented to journalist P il n N Chiar in at the Oireachtas na Samhna in Belfast tomorrow, Saturday 1 November,...
31/10/2025
RT lyric fm is calling for choirs across Ireland to share their festive music-m...
31/10/2025
Three awards were presented to RT Raidi na Gaeltachta broadcasters at the Oire...
31/10/2025
RT continues its proud tradition of championing Ireland's vibrant arts and cultural landscape through its RT Supporting the Arts initiative. This November...
31/10/2025
RT selects Irish independent production company to produce Christian Worship on...
31/10/2025
Amidst Gyeongju, South Korea's ancient temples and modern skylines, Jensen H...
30/10/2025
Midwich has signed a UK and Ireland distribution deal with X2O Media, a worldwid...
30/10/2025
SVG Students To Watch: Sam Newitt, Kansas State UniversityThe South Dakota native thrives in many roles behind the scenes at K-StateHD.TVBy Brandon Costa, Direc...
30/10/2025
SVG Sit-Down: Swerve Sports' Christy Tanner Explores the Young FAST Channel&...
30/10/2025
SVG Campus Shot Callers: Andy Liebsch, Senior Director, Video Services, Kansas S...
30/10/2025
Diversified Names Paul Lidsky CEO, Expanding Leadership Role After Serving as Bo...
30/10/2025
NBA, Cosm Enter Long-Term Partnership for Shared Reality Production, Distributio...
30/10/2025
SVG New Sponsor Spotlight: FanConnect's Brett Crossley on Reimagining the Ga...
30/10/2025
FanDuel Sports Network to Deliver Select Live NBA, NHL Games to Major Streaming ...
30/10/2025
As the year comes to a close, we can feel the invigorating wind sweeping in for ...
30/10/2025
By Bailey Pennick
One of the most exciting things about the Sundance Film Festi...
30/10/2025
The SGL Carbon site in Bonn has a long tradition of training. For many years, young talent has been successfully trained here, regularly achieving excellent exa...
30/10/2025
SBS, NITV and Screen Australia announce 2025 Digital Originals Shortlist
29 October, 2025
Media releases
SBS, NITV and Screen Australia are excited to unve...
30/10/2025
Jon Rambeau, President of Integrated Mission Systems at L3Harris Technologies, speaks about industrial collaboration at the Asia-Pacific Economic Cooperation (A...