
HP Research Reveals Nine out of 10 Mobile Applications Vulnerable to Attack
NEW YORK - HP today released results from a research study revealing that mobile applications represent a real security threat, with vulnerabilities affecting nine out of 10 mobile applications published by a representative sample of companies on the Forbes Global 2000.
According to the study, 97 percent of the mobile applications tested accessed at least one private information source within a device, and 86 percent of those applications did not have adequate security measures in place to protect them from the most common exploits.
As computing becomes borderless, adversaries are increasingly bypassing perimeter security with ease and taking advantage of vulnerabilities brought on by the growing number of applications and entry points. According to Gartner, Inc., mobile app stores will see annual downloads reach 102 billion in 2013, up from 64 billion in 2012.(1) This spike in demand is pushing business managers to dramatically increase the speed at which they deploy mobile applications, and driving more of the development to third parties. This results in less oversight of security, and emphasizes the need for a mobile security strategy that enables businesses to go from fast to market to secure and fast to market.
While mobile devices are becoming more and more critical to conducting business, they are also becoming prime targets for attack, with vulnerable applications providing access to sensitive data, said Mike Armistead, vice president and general manager, Enterprise Security Products, Fortify, HP. Mobile applications now are the first line of defense against the adversary and organizations must be equipped to assess, assure and protect these applications to prevent damage from exploits.
Sensitive corporate data and personal information are often housed side by side on insecure devices. This introduces unnecessary vulnerabilities that can be easily resolved if they are identified and addressed. The HP research study leveraged HP Fortify on Demand to scan more than 2,100 mobile applications from more than 600 companies, revealing alarming realities regarding the sheer number of applications vulnerable to attack.
The most common and easily addressable vulnerability sources reported include:
Privacy issues: Of 2,107 mobile applications scanned, 97 percent accessed private data sources including personal address books, social media pages and connectivity options like Bluetooth or Wi-Fi. Of those applications, 86 percent did not have adequate security measures in place to protect them from the most common exploits, such as misuse of unencrypted data, cross-site scripting and insecure transmission of data.
Lack of binary protections: 86 percent of applications tested lacked binary hardening, leaving applications vulnerable to information disclosure, buffer overflows and poor performance. To ensure security throughout the life cycle of the application, it is essential to build in the best security practices from conception.
Insecure data storage: 75 percent of applications did not use proper encryption techniques when storing data on mobile devices, which leaves unencrypted data accessible to an attacker. This data includes passwords, personal information, session tokens, documents, chat logs and photos. Unencrypted data that is seen and used by a malicious attacker can violate numerous corporate governance policies as well as compromise the reputation of the enterprise if sensitive trade secrets are leaked to competitors, the media or any other variety of recipients with negative consequences.
Transport security: 18 percent of applications tested sent user names and passwords over HTTP. Of the remaining 82 percent, 18 percent incorrectly implemented SSL/HTTPS. These unprotected credentials are typically used not only for the mobile applications but also by their web application counterparts. This further compounds the issue, since malicious attackers on the same network could then sniff that data.
Laying the groundwork for a basic mobile application security strategy allows organizations to identify vulnerabilities before they are exploited. Nearly all vulnerabilities can be found and remediated by simply running a security assessment test before releasing or procuring a mobile application. This can identify the most common vulnerabilities and assess whether data is being passed maliciously or stored insecurely. HP Fortify on Demand for Mobile enables organizations to assess vulnerabilities across mobile applications, assure security flaws are resolved before deployment, and protect applications from attacks once in production.
Software development is not a perfect science-but it was imperative that we had a robust security assurance process in place to protect our credit union members, said Atul Varde, SVP and CIO, Affinity Credit Union. With emerging technologies such as mobile applications, where things are changing at a very rapid pace, the sort of independent experience and oversight that HP Fortify on Demand provides makes the whole process more secure.
Methodology
Conducted by HP Security Research (HPSR), the mobile application security study tested the security posture of 2,107 applications published by 601 companies on the Forbes Global 2000. The companies represented 50 countries across 76 industries. Applications were selected from 22 categories such as productivity and social networking, and were tested using the HP Fortify on Demand automated binary and dynamic analysis engine. Application testing was conducted during October and November 2013.
Additional information about mobile application security and further details resulting from the study are available at www.hp.com/go/fortifymobile.
(1) Gartner Press Release; Gartner Says Mobile App Stores Will See Annual Download
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
04/08/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
04/07/2026
April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
23/05/2026
In its second year as rightsholder, FOX Sports goes bigger across the board for ...
23/05/2026
Tonight's MLS matchup between the LA Galaxy and the Houston Dynamo FC will m...
23/05/2026
AI-powered vocal tool gains first new language expansion
IK Multimedia's AI-powered voice-creation software has seen a number of updates since it launch...
23/05/2026
Nielsen Global Leadership Network graduates celebrate Earth Day 2026
Nielsen vo...
23/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
23/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
23/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
23/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
22/05/2026
Germany's Magenta TV, which will have 44 exclusive FIFA World Cup match broa...
22/05/2026
DAZN, the world's leading sports entertainment platform, has acquired global broadcast rights to the International Federation of American Football's ( I...
22/05/2026
ATHLOS, the all-women's professional track and field league, has announced i...
22/05/2026
The National Academy of Television Arts & Sciences (NATAS) today announced that the 47th Annual Sports Emmy Awards and the 47th Annual News & Documentary Emmy A...
22/05/2026
Wooden Camera today announced the release of new accessories for the Blackmagic URSA Cine Immersive. The new lineup includes a redesigned Top Plate and Side Rai...
22/05/2026
YES Network and OTT Advisors have announced a sixth consecutive season of their streaming partnership, continuing their collaboration on the Gotham app. OTT Adv...
22/05/2026
NESN, New England's premier sports network, will again turn its camera to Fe...
22/05/2026
Dale Pro Audio is hosting an RF over Fiber Livestream Webinar on May 28 from 1-2:30 pm EST. With major sporting events and large-scale productions putting incre...
22/05/2026
Audio-Technica has announced key leadership appointments designed to further strengthen its sales organization and drive continued growth across the Americas. M...
22/05/2026
After nearly four decades shaping the global combat sports landscape, Scott Coker has announced a powerful return as he looks to build a new international mixed...
22/05/2026
Skyline Communications, the company behind the globally deployed DataMiner xOps platform, today announced the launch of xOps Vanguard Runway, a strategic accele...
22/05/2026
For the fully onsite production, 30 cameras - including a SkyCam and Megalodon - will capture the action in Texas
One of the world's biggest rodeo producti...
22/05/2026
Leading Argentina-based sports media company Torneos y Competencias S.A. has modernized its playout operations, implementing a fully redundant, multichannel env...
22/05/2026
As the 2026 Major League Pickleball season kicks off this weekend in Dallas, it ...
22/05/2026
Shure has become a minority investor in Edge Sound Research, a start-up company that is developing new experiential audio technologies that redefine how many au...
22/05/2026
In advance of this year's Sports Emmy Awards, SVG is taking a deep dive into...
22/05/2026
The National Hockey League (NHL) and Amazon Music announced that GRAMMY Award-winning superstar Jelly Roll will provide the official theme song of the 2026 Stan...
22/05/2026
David Pogue will keynote SVV Summer Camp and discuss Apple at 50: How the World...
22/05/2026
In its second year as rightsholder, FOX Sports goes bigger across the board for ...
22/05/2026
The broadcaster is drawing on lessons learned in its first year of covering the ...
22/05/2026
At our 2026 Investor Day, we shared an inside look at the rebuild of our advertising business. This pivot to our own purpose-built platform is already driving s...
22/05/2026
Podcasting on Spotify continues to grow, and so do the ways listeners engage with it. At Investor Day 2026, we shared how we're building the next chapter of...
22/05/2026
Limited-time collections now available
Restoration experts CEDAR Audio have recently launched a new line of Icons plug-ins that make their powerful processo...
22/05/2026
Three new classics join Model Pass line-up
Boss' PX-1 Plugout Pedal offers an innovative approach to guitar pedals, providing users with a hardware stom...
22/05/2026
At its Meitingen site, SGL Carbon has implemented two key projects to further de...
22/05/2026
Statement regarding 2026 National NAIDOC Lifetime Achievement Award for the late...
22/05/2026
Latest data reveals steady distributor rankings, a seasonal shift toward digital...
22/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
22/05/2026
Amagi Media Labs Limited (NSE: AMAGI, BSE: 544679), a cloud-native SaaS platform providing AI-enabled solutions to global media and entertainment companies, tod...
22/05/2026
An nima Post Relies on Cintel to Revive Classic Mexican Films
Brie Clayton May 22, 2026
0 Comments
Film scanner and DaVinci Resolve Studio help manage...
22/05/2026
Boris FX Sapphire Adds Optical Beauty and Hypnotic Textures
Jessie Electa Petrov May 22, 2026
0 Comments
The 2026.5 release introduces advanced defocu...
22/05/2026
Deployment Preserves Trusted Workflows While Enabling a Path to UHD and SMPTE ST 2110
Leading Argentina-based sports media company Torneos y Competencias S.A....
22/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
22/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
22/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
22/05/2026
Back to All News
Ex-Husband, Current Husband, One Wild Rescue: Korean Action Co...
22/05/2026
Catch the latest in Irish music live from venues such as Whelan's, R is n Du...
21/05/2026
Game Creek Video Columbia and Celtic, NEP Supershooter 8 will house onsite produ...