Mobile App Security: Identifying and Fixing Hidden Vulnerabilities with BeVigil
ID: a16330e2-c829-5edc-8d6c-eac7baac1f9b
STIX ID: report--a16330e2-c829-5edc-8d6c-eac7baac1f9b
Feed Name: CloudSEK Blog
BeVigil's mobile app scanner discovered hardcoded Salesforce credentials (client ID, client secret, username/password) and retrievable access tokens in a widely used Android app, along with exposed API endpoints that permit obtaining access tokens and querying Salesforce APIs for user, partner PII, and customer data. The report outlines the discovery, demonstrates how tokens can be used to fetch sensitive information, and recommends mitigations including revoking keys, proxying API requests through a backend, enforcing role-based access controls, regular token rotation, audits, and real-time monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
