logo

Mobile App Security: Identifying and Fixing Hidden Vulnerabilities with BeVigil

ID: a16330e2-c829-5edc-8d6c-eac7baac1f9b

STIX ID: report--a16330e2-c829-5edc-8d6c-eac7baac1f9b

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2025-02-19

Date Updated: 2026-04-27

...
...

BeVigil's mobile app scanner discovered hardcoded Salesforce credentials (client ID, client secret, username/password) and retrievable access tokens in a widely used Android app, along with exposed API endpoints that permit obtaining access tokens and querying Salesforce APIs for user, partner PII, and customer data. The report outlines the discovery, demonstrates how tokens can be used to fetch sensitive information, and recommends mitigations including revoking keys, proxying API requests through a backend, enforcing role-based access controls, regular token rotation, audits, and real-time monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.