Sony Pixel Power calrec Sony

HP Research Reveals Nine out of 0 Mobile Applications Vulnerable to Attack

18/11/2013

HP Research Reveals Nine out of 10 Mobile Applications Vulnerable to Attack

NEW YORK - HP today released results from a research study revealing that mobile applications represent a real security threat, with vulnerabilities affecting nine out of 10 mobile applications published by a representative sample of companies on the Forbes Global 2000.

According to the study, 97 percent of the mobile applications tested accessed at least one private information source within a device, and 86 percent of those applications did not have adequate security measures in place to protect them from the most common exploits.

As computing becomes borderless, adversaries are increasingly bypassing perimeter security with ease and taking advantage of vulnerabilities brought on by the growing number of applications and entry points. According to Gartner, Inc., mobile app stores will see annual downloads reach 102 billion in 2013, up from 64 billion in 2012.(1) This spike in demand is pushing business managers to dramatically increase the speed at which they deploy mobile applications, and driving more of the development to third parties. This results in less oversight of security, and emphasizes the need for a mobile security strategy that enables businesses to go from fast to market to secure and fast to market.

While mobile devices are becoming more and more critical to conducting business, they are also becoming prime targets for attack, with vulnerable applications providing access to sensitive data, said Mike Armistead, vice president and general manager, Enterprise Security Products, Fortify, HP. Mobile applications now are the first line of defense against the adversary and organizations must be equipped to assess, assure and protect these applications to prevent damage from exploits.

Sensitive corporate data and personal information are often housed side by side on insecure devices. This introduces unnecessary vulnerabilities that can be easily resolved if they are identified and addressed. The HP research study leveraged HP Fortify on Demand to scan more than 2,100 mobile applications from more than 600 companies, revealing alarming realities regarding the sheer number of applications vulnerable to attack.

The most common and easily addressable vulnerability sources reported include:

Privacy issues: Of 2,107 mobile applications scanned, 97 percent accessed private data sources including personal address books, social media pages and connectivity options like Bluetooth or Wi-Fi. Of those applications, 86 percent did not have adequate security measures in place to protect them from the most common exploits, such as misuse of unencrypted data, cross-site scripting and insecure transmission of data.

Lack of binary protections: 86 percent of applications tested lacked binary hardening, leaving applications vulnerable to information disclosure, buffer overflows and poor performance. To ensure security throughout the life cycle of the application, it is essential to build in the best security practices from conception.

Insecure data storage: 75 percent of applications did not use proper encryption techniques when storing data on mobile devices, which leaves unencrypted data accessible to an attacker. This data includes passwords, personal information, session tokens, documents, chat logs and photos. Unencrypted data that is seen and used by a malicious attacker can violate numerous corporate governance policies as well as compromise the reputation of the enterprise if sensitive trade secrets are leaked to competitors, the media or any other variety of recipients with negative consequences.

Transport security: 18 percent of applications tested sent user names and passwords over HTTP. Of the remaining 82 percent, 18 percent incorrectly implemented SSL/HTTPS. These unprotected credentials are typically used not only for the mobile applications but also by their web application counterparts. This further compounds the issue, since malicious attackers on the same network could then sniff that data.

Laying the groundwork for a basic mobile application security strategy allows organizations to identify vulnerabilities before they are exploited. Nearly all vulnerabilities can be found and remediated by simply running a security assessment test before releasing or procuring a mobile application. This can identify the most common vulnerabilities and assess whether data is being passed maliciously or stored insecurely. HP Fortify on Demand for Mobile enables organizations to assess vulnerabilities across mobile applications, assure security flaws are resolved before deployment, and protect applications from attacks once in production.

Software development is not a perfect science-but it was imperative that we had a robust security assurance process in place to protect our credit union members, said Atul Varde, SVP and CIO, Affinity Credit Union. With emerging technologies such as mobile applications, where things are changing at a very rapid pace, the sort of independent experience and oversight that HP Fortify on Demand provides makes the whole process more secure.

Methodology

Conducted by HP Security Research (HPSR), the mobile application security study tested the security posture of 2,107 applications published by 601 companies on the Forbes Global 2000. The companies represented 50 countries across 76 industries. Applications were selected from 22 categories such as productivity and social networking, and were tested using the HP Fortify on Demand automated binary and dynamic analysis engine. Application testing was conducted during October and November 2013.

Additional information about mobile application security and further details resulting from the study are available at www.hp.com/go/fortifymobile.

(1) Gartner Press Release; Gartner Says Mobile App Stores Will See Annual Download
LINK: http://www8.hp.com/us/en/hp-news/press-release.html?id=1528865...
See more stories from hp

Most recent headlines

05/01/2027

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be demoed at CES 2026

Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...

01/06/2026

Dolby Sets the New Standard for Premium Entertainment at CES 2026

January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026 Throughout the week, Dolby brings to life the latest innovatio...

01/05/2026

NBCUniversal's Peacock to Be First Streamer to Integrate Dolby's Full Suite of Premium Picture and Sound Innovations

January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...

01/04/2026

DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION

January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION Douyin Users Can Now Create And Share Videos With Stun...

09/01/2026

Rock-It Sports' Deron Brown & Laura Rowlands on Launching a New Brand, Supplying Logistical Needs for Events in 2026

Rock-It Sports' Deron Brown & Laura Rowlands on Launching a New Brand, Suppl...

09/01/2026

Warner Bros. Discovery's Chris Brown on the Broadcaster's First French Open, Advancing Remote Workflows at Techwood Facility

Warner Bros. Discovery's Chris Brown on the Broadcaster's First French O...

09/01/2026

NFL Playoffs 2026: CBS Sports Travels to Jacksonville With Packed Arsenal of Production Capabilities

NFL Playoffs 2026: CBS Sports Travels to Jacksonville With Packed Arsenal of Pro...

09/01/2026

NFL Playoffs 2026: NBC Sports Is Set To Roll Out New Scorebar, Insert Graphics This Weekend

NFL Playoffs 2026: NBC Sports Is Set To Roll Out New Scorebar, Insert Graphics T...

09/01/2026

NFL Playoffs 2026: Prime Video Production Team Caps Historic Season With Iconic Bears-Packers Primetime Matchup in Chicago

NFL Playoffs 2026: Prime Video Production Team Caps Historic Season With Iconic ...

09/01/2026

NFL Playoffs 2026: FOX Sports Kicks Off Postseason Slate With Two-Game Wild Card Coverage

NFL Playoffs 2026: FOX Sports Kicks Off Postseason Slate With Two-Game Wild Card...

09/01/2026

NFL Playoffs 2026: ESPN's Run Brings Monday Night Football' Flagship Operation Into January

NFL Playoffs 2026: ESPN's Run Brings Monday Night Football' Flagship Op...

09/01/2026

Carr: FCC Looking for Ways to Empower' Local Broadcasters

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

09/01/2026

Panasonic to Introduce Projection, LED and Workflow Offerings at ISE 2026

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

09/01/2026

SMPTE Announces 2026 Leadership

SMPTE , the home of media professionals, technologists, and engineers, today introduced the board officers and regional governors who will serve terms beginning...

09/01/2026

Globecast Appoints Chris Pulis as Group Chief Technology...

Globecast, the leading provider of broadcast, media and entertainment managed services, today announced the appointment of Chris Pulis as Group Chief Technology...

09/01/2026

Hollywood Professional Association Announces Updates to B...

The Hollywood Professional Association (HPA) today announced several updates to its board of directors. As part of HPA s annual governance cycle, new leadership...

09/01/2026

SDVI APPOINTS SIMON ELDRIDGE AS CHIEF OPERATING OFFICER

SDVI, the leading platform provider for cloud-native media supply chains, today announced that Simon Eldridge has been appointed chief operating officer. In thi...

09/01/2026

Cobalt Digital Returns to ISE with Comprehensive Lineup o...

Cobalt Digital, the leading designer and manufacturer of award-winning ST 2110 and SDI signal processing products, and a founding partner in the openGear initi...

09/01/2026

iWedia Strengthens Leadership in ATSC 3-0 with Market-Pro...

iWedia, a global leader in connected TV software solutions, announces that its market-proven ATSC 3.0 software stack is powering the broadcast functionality of ...

09/01/2026

Amino and Xibo Partner to Deliver Next Generation 4K Digi...

Amino, a global leader in enterprise video and digital signage technology, today announced a strategic partnership with Xibo, a leading global digital signage s...

09/01/2026

FIFA Strikes Content Deal with TikTok for 2026 World Cup

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

09/01/2026

HPA Elects New Officers, Board Members for 2026

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

09/01/2026

NFL's 2025-26 Regular Season Is Second-Most-Watched Ever

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

09/01/2026

FCC Sets Tentative Agenda for Jan. 29 Open Meeting

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

09/01/2026

Carr: FCC Looking for Ways to 'Empower' Local Broadcasters

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

09/01/2026

RT delivers another record year in 2025, bringing Ireland together with national moments

RT Player has 157 million streams, up 10% year-on-year An increase on 2024, RT...

09/01/2026

2FM announces line-up of Rising Artists for 2026

RT 2FM has today announced the highly anticipated list of 2FM Rising Artists for 2026, kicking off 2FM Rising week for the eighth year on The Tracy Clifford Sh...

09/01/2026

RT to Host the 2026 RTS Ireland Awards

RT to Host the 2026 RTS Ireland Awards Thursday, 16 April 2026 | Dublin Royal Convention Centre The RTS Ireland Television Awards 2026 | Gradaim RTS 2026 | R...

09/01/2026

NVIDIA Unveils Multi-Agent Intelligent Warehouse and Catalog Enrichment AI Blueprints to Power the Retail Pipeline

Every that was easy shopping moment is made possible by teams working to hit s...

08/01/2026

How disinformation is shaping Sudan's conflict: a new report

An evidence-based analysis on disinformation and information manipulation in Sudan's ongoing conflict is published today. (January 8th 2026). Thomson Found...

08/01/2026

At CFP Semifinals, ESPN Again Flexes Its Operational Muscle With 20+ MegaCast Viewing Options

At CFP Semifinals, ESPN Again Flexes Its Operational Muscle With 20+ MegaCast Vi...

08/01/2026

SVG Students To Watch: Sophie Fowler, University of Oregon

SVG Students To Watch: Sophie Fowler, University of OregonThe Portland product has honed her skills as a producer, director, and TD at Quack VideoBy Brandon Cos...

08/01/2026

Follow the Money, Episode 3: Inside the Sports-Media Biz With Sam McCleery and Ken Aagaard

Follow the Money, Episode 3: Inside the Sports-Media Biz With Sam McCleery and K...

08/01/2026

SVG New Sponsor Spotlight: Qualstar's Jeff Sengpiehl on the Enduring Power and Value of LTO Tape for Video Archiving

SVG New Sponsor Spotlight: Qualstar's Jeff Sengpiehl on the Enduring Power a...

08/01/2026

Legendary February: Production Leaders at NBC Sports Pull Back the Curtain on Olympics, Super Bowl, NBA All-Star Plans

Legendary February: Production Leaders at NBC Sports Pull Back the Curtain on Ol...

08/01/2026

One Year In: How Creators Are Growing Their Shows and Connecting With Audiences Through the Spotify Partner Program

In 2025 we launched the Spotify Partner Program to give creators more ways to tu...

08/01/2026

Spotify Toasts to the Future of Podcasting With Creators at Our New Sycamore Studios

On Wednesday in Los Angeles, Spotify welcomed creators and press to a brunch cel...

08/01/2026

Hollywood Professional Association (HPA) Announces Updates to Board of Directors

The Hollywood Professional Association (HPA) today announced several updates to its Board of Directors. As part of HPA's annual governance cycle, new leader...

08/01/2026

Chyron Releases Virtual Placement 8.0

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

08/01/2026

SMPTE Names Board Officers, Governors for 2026

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

08/01/2026

FCC to Vote on Proposals Expanding Unlicensed Use of 6 GHz Band

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

08/01/2026

RTVE selects Alfalite Neopix for its first broadcast depl...

Spain's national public broadcaster, RTVE, has upgraded one of its main television production facilities in Madrid with the installation of two Alfalite NEO...

08/01/2026

Richard E. Wiley to Step Down as Media Institute's Chairman

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

08/01/2026

Cineverse Acquires Giant Worldwide

Share Share by: Copy link Facebook X Whatsapp Pinterest Flipboard...

08/01/2026

Maxon Introduces Cinebench 2026

Maxon's new release of Cinebench features performance enhancements and adds support for the latest Nvidia and AMD GPUs as well as Apple Silicon. Maxon is t...

08/01/2026

Zixi Accelerates Global Growth with Appointment of Heathe...

Zixi, the industry leader in IP-based video transport and orchestration, today announced the appointment of Heather Mellish as Vice President, Global Sales. In...

08/01/2026

Pebble future-proofs playout at Canal Sur

Pebble, the leading automation, content management and integrated channel specialist, has provided a complete update of its installation at Canal Sur in Spain. ...

08/01/2026

Panasonics success in US market with Flagship Z95B OLED T...

iWedia, a global leader in software solutions for connected TV devices, proudly announces the success of its collaboration with Panasonic on the Z95B OLED TV, o...

08/01/2026

Secuoya Chile Invests in Ikegami UHK-X600 and UHL-X40 Cam...

Secuoya Chile, a leading provider of television content creation and supporting services, has invested in Ikegami UHK-X600 and UHL-X40 broadcast cameras as the ...

08/01/2026

Kiloview Highlights its Integrated AV-over-IP Ecosystem a...

Kiloview, a global leader in AV-over-IP solutions, will showcase its latest innovations at ISE 2026, highlighting the continued evolution of its complete, light...