
HP Research Reveals Nine out of 10 Mobile Applications Vulnerable to Attack
NEW YORK - HP today released results from a research study revealing that mobile applications represent a real security threat, with vulnerabilities affecting nine out of 10 mobile applications published by a representative sample of companies on the Forbes Global 2000.
According to the study, 97 percent of the mobile applications tested accessed at least one private information source within a device, and 86 percent of those applications did not have adequate security measures in place to protect them from the most common exploits.
As computing becomes borderless, adversaries are increasingly bypassing perimeter security with ease and taking advantage of vulnerabilities brought on by the growing number of applications and entry points. According to Gartner, Inc., mobile app stores will see annual downloads reach 102 billion in 2013, up from 64 billion in 2012.(1) This spike in demand is pushing business managers to dramatically increase the speed at which they deploy mobile applications, and driving more of the development to third parties. This results in less oversight of security, and emphasizes the need for a mobile security strategy that enables businesses to go from fast to market to secure and fast to market.
While mobile devices are becoming more and more critical to conducting business, they are also becoming prime targets for attack, with vulnerable applications providing access to sensitive data, said Mike Armistead, vice president and general manager, Enterprise Security Products, Fortify, HP. Mobile applications now are the first line of defense against the adversary and organizations must be equipped to assess, assure and protect these applications to prevent damage from exploits.
Sensitive corporate data and personal information are often housed side by side on insecure devices. This introduces unnecessary vulnerabilities that can be easily resolved if they are identified and addressed. The HP research study leveraged HP Fortify on Demand to scan more than 2,100 mobile applications from more than 600 companies, revealing alarming realities regarding the sheer number of applications vulnerable to attack.
The most common and easily addressable vulnerability sources reported include:
Privacy issues: Of 2,107 mobile applications scanned, 97 percent accessed private data sources including personal address books, social media pages and connectivity options like Bluetooth or Wi-Fi. Of those applications, 86 percent did not have adequate security measures in place to protect them from the most common exploits, such as misuse of unencrypted data, cross-site scripting and insecure transmission of data.
Lack of binary protections: 86 percent of applications tested lacked binary hardening, leaving applications vulnerable to information disclosure, buffer overflows and poor performance. To ensure security throughout the life cycle of the application, it is essential to build in the best security practices from conception.
Insecure data storage: 75 percent of applications did not use proper encryption techniques when storing data on mobile devices, which leaves unencrypted data accessible to an attacker. This data includes passwords, personal information, session tokens, documents, chat logs and photos. Unencrypted data that is seen and used by a malicious attacker can violate numerous corporate governance policies as well as compromise the reputation of the enterprise if sensitive trade secrets are leaked to competitors, the media or any other variety of recipients with negative consequences.
Transport security: 18 percent of applications tested sent user names and passwords over HTTP. Of the remaining 82 percent, 18 percent incorrectly implemented SSL/HTTPS. These unprotected credentials are typically used not only for the mobile applications but also by their web application counterparts. This further compounds the issue, since malicious attackers on the same network could then sniff that data.
Laying the groundwork for a basic mobile application security strategy allows organizations to identify vulnerabilities before they are exploited. Nearly all vulnerabilities can be found and remediated by simply running a security assessment test before releasing or procuring a mobile application. This can identify the most common vulnerabilities and assess whether data is being passed maliciously or stored insecurely. HP Fortify on Demand for Mobile enables organizations to assess vulnerabilities across mobile applications, assure security flaws are resolved before deployment, and protect applications from attacks once in production.
Software development is not a perfect science-but it was imperative that we had a robust security assurance process in place to protect our credit union members, said Atul Varde, SVP and CIO, Affinity Credit Union. With emerging technologies such as mobile applications, where things are changing at a very rapid pace, the sort of independent experience and oversight that HP Fortify on Demand provides makes the whole process more secure.
Methodology
Conducted by HP Security Research (HPSR), the mobile application security study tested the security posture of 2,107 applications published by 601 companies on the Forbes Global 2000. The companies represented 50 countries across 76 industries. Applications were selected from 22 categories such as productivity and social networking, and were tested using the HP Fortify on Demand automated binary and dynamic analysis engine. Application testing was conducted during October and November 2013.
Additional information about mobile application security and further details resulting from the study are available at www.hp.com/go/fortifymobile.
(1) Gartner Press Release; Gartner Says Mobile App Stores Will See Annual Download
Most recent headlines
06/10/2025
France T l visions, France's leading broadcaster, has received the 2025 EBU ...
04/09/2025
Monumental Sports & Entertainment (MSE), in collaboration with Dalet, has been a...
07/08/2025
July 8 2025, 22:30 (PDT) Tata Motors & Dolby Bring Dolby Atmos to Harrier.ev, R...
12/07/2025
As the death toll continues to mount, with at least 120 killed and more than 170 people still missing on July 10 from devastating Texas floods, a number of broa...
12/07/2025
EL SEGUNDO, Calif., and MIAMI -DirecTV and TelevisaUnivision have signed a deal that will make the ad-supported premium subscription tier of ViX, ViX Premium wi...
11/07/2025
PARK CITY, UTAH, July 11, 2025 - The nonprofit Sundance Institute announced today the 11 producers chosen for its annual Producers Labs, returning to Ucross Fou...
11/07/2025
If you've ever wondered what might be playing in Clark Kent's headphones...
11/07/2025
L3Harris Technologies President of Intelligence, Surveillance and Reconnaissance Jason Lambert and General Manager of L3Harris Waco facility Sean Ling held a ce...
11/07/2025
ARLINGTON, Va. WETA, the flagship public media station in the national capital area, has launched WETA+, a new streaming service tailored for the local Washingt...
11/07/2025
The Federal Communications Commission has emerged as one of the central players in the broadcast TV landscape in 2025, with its deregulatory policies sparking h...
11/07/2025
Calrec will introduce usability, customization and system enhancements across its entire range of Argo consoles during IBC2025, Sept. 12-15, at the RAI Amsterda...
11/07/2025
LONDON Encompass Digital Media said it will support live and on-demand viewing of the 2025 FIFA Club World Cup across multiple global regions for sports enterta...
11/07/2025
Two-thirds of broadcast engineers reaped the benefits of a pay raise within the last year....
11/07/2025
CARY, N.C. SmallHD has launched the Quantum 27, a new 26.5-inch Quantum-Dot OLED monitor designed to deliver postproduction image quality in a compact, set-frie...
11/07/2025
The Federal Communications Commission's Enforcement Bureau and Tegna have entered into a consent decree that will settle an investigation into the accidenta...
11/07/2025
WASHINGTON Following news in early July that Paramount had settled President Donald Trump's lawsuit, Sens. Edward J. Markey (D-Mass.) and Ben Ray Luj n (D-N...
11/07/2025
Model/Actriz Performs Lead Single Cinderella on The Late Show with Stephen Colbe...
11/07/2025
Behind the Mic: Amazon Prime Preps for First Season of NBA Action; MSG Networks ...
11/07/2025
SVG New Sponsor Spotlight: Suite Studios' Craig Hering on Adapting to Client...
11/07/2025
2025 SVG Content Management Forum Breaks Down AI's Impact, Continued Transit...
11/07/2025
A Journey HOME: University of Nebraska's HuskerVision Goes IP Leaders from the HuskerVision and Lawo share their IP learnings By SVG Staff
Friday, July 1...
11/07/2025
CMSI, Remote Picture Labs, Ace ESPN's Cloud-Based Editing Efforts for Wimble...
11/07/2025
Netflix Enters the Live-Boxing-Production Ring for Round 2 With Historic Taylor-...
11/07/2025
Back to All News
Too Hot to Handle: Italy Is Coming on July 18 Only on Netflix
Entertainment
11 July 2025
GlobalItaly
Link copied to clipboard
July 11, 20...
11/07/2025
Back to All News
Netflix Will Release Death Inc. Seasons 1, 2 and 3
Entertainment
11 July 2025
GlobalSpain
Link copied to clipboard
Season 1
Season 2
Se...
11/07/2025
AI and Multimedia Authenticity Standards Collaboration launches two papers to guide the future of AI integration, today at the AI for Good Global Summit
The...
11/07/2025
Ceramics - the humble mix of earth, fire and artistry - have been part of a global conversation for millennia.
From Tang Dynasty trade routes to Renaissance pa...
10/07/2025
The current holder of the prestigious Thomson Foundation Young Journalist of the Year Award has been forced to stop reporting over fears for her safety in Afgha...
10/07/2025
Spotify is turning up the volume on Australian music with a multipronged initiative designed to highlight the dominance of Australian artists on the global stag...
10/07/2025
This is not a drill: Oasis is back on the road-marking its first live performanc...
10/07/2025
The music industry depends on fresh ideas, bold voices, and emerging talent. Yet across the U.K., too many young musicians lack the space to develop their craft...
10/07/2025
NEW YORK - July 10, 2025 - Nielsen, the global leader in audience measurement, data and analytics, today announced that it appointed Richard Pacheco as head of ...
10/07/2025
Local newscasts don't exist in a vacuum. News directors and station management constantly evaluate what's working, what isn't and perhaps most impor...
10/07/2025
Lawo has announced that Stuttgart Media University (Hochschule der Medien, HdM) has comprehensively modernized its central recording studio after selecting an I...
10/07/2025
The Society of Motion Picture and Television Engineers (SMPTE) has opened early-bird registration for the Media Technology Summit, which will take place in a ne...
10/07/2025
NASHVILLE, Tenn. TNDV Television has launched Aspiration 35, a new version of its 40-foot Aspiration truck reimagined for cinematic multicamera productions....
10/07/2025
BURBANK, Calif. Key Code Education, a provider of instructor-led postproduction training, is growing its curriculum with new programs for beginner and intermedi...
10/07/2025
HACKENSACK, N.J. Actus Digital will demonstrate how broadcasters can transform compliance monitoring from a necessary expense into a strategic revenue driver at...
10/07/2025
The Federal Register has published a summary of the Federal Communications Commission's Public Notice seeking comments on its ownership rules that lists a d...
10/07/2025
Back to All News
Netflix Presents the Official Trailer for SuperestarPlay Video
Play Video
Entertainment
10 July 2025
GlobalSpain
Link copied to clipboard...
10/07/2025
In the race to understand our planet's changing climate, speed and accuracy are everything. But today's most widely used climate simulators often strugg...
10/07/2025
As one of the world's largest emerging markets, Indonesia is making strides toward its Golden 2045 Vision - an initiative tapping digital technologies and...
10/07/2025
10 Jul 2025
VEON and Cohen Circle Secure Investor Commitments for Kyivstar Listing Kyiv, New York, Dubai, and Philadelphia - July 10, 2025 - VEON Ltd. (Nasdaq:...
10/07/2025
5G for all? What the DFL's use of Easy5G and RefCam could mean for events in...
10/07/2025
Save the Date: PGA TOUR Studios Welcomes SVG Remote Production Summit on Oct 14-...
10/07/2025
Cloud on the Road: How Remote-Production-Service Providers Are Adapting to a New...
10/07/2025
Seattle Kraken's Ryan Schaber on the NHL Team Taking Live Game Productions I...
10/07/2025
FOX Sports Reboots Small Control Room in Los Angeles as Hub for Vertical-First P...
10/07/2025
SVG Sit-Down: MSE's Zach Leonsis, ViewLift's Rick Allen Go Deep on Joint...