In a world where business is increasingly conducted on mobile devices, it is imperative that organizations offer mobile applications to serve their customer base. In fact, for many businesses, mobile applications are one of the primary channels used to interact with customers and to sell products and services.
Developing a secure mobile application can be challenging. Significant security risks are introduced when these applications are not continuously monitored for new vulnerabilities and potential threats. Take, for example, the recent Under Armour “My Fitness Pal” application breach. The security incident caused serious damage; in addition to impacting roughly 150 million users, public shares fell nearly 5% just days after the breach was announced.
As mobile applications continue to pose looming threats, Bitsight researchers leveraged data from their mobile application security risk vector to identify if mobile applications offered on iOS and Google Play stores have known security vulnerabilities and issues.
Our Methodology
Bitsight examined representative samples of more than 1,000 companies in each of the following industry sectors that offer mobile applications on iOS and Google Play:
- Business Services: Consumer Services, Human Resources, Management Consulting, Marketing and Advertising, Logistics and Supply Chain companies.
- Finance: Banking, Investment Management, Venture Capital, and Private Equity companies.
- Technology: Software, Networking, Security, Medical Devices, and Semiconductor companies.
- Education: Higher Education, Primary/Secondary Education, E-Learning, and Education Management companies.
- Media/Entertainment: Music, News, Media, Publishing, and Entertainment companies.
Mobile applications were tested for known security vulnerabilities and issues that are documented in The Common Vulnerability Scoring System (CVSS), a free and open industry standard for assessing security vulnerabilities.
Based on the data, Bitsight uncovered industries that are most often faced with mobile application security challenges. We looked at the rate of companies in each industry that offer at least one mobile application that did not pass a high severity test: a CVSS score of 7 and above qualifies as high severity.
What We Learned
The results show that many industries are offering a significant percentage of mobile applications that have high severity vulnerabilities. These vulnerabilities include (but are not limited to): data leakage, privilege abuse, unencrypted personally identifiable information (PII), and credential theft.

