TL;DR: OWASP released MASWE v1.0.0 on Aug. 17, 2026, the first stable version of the Mobile Application Security Weakness Enumeration and the missing middle layer between the OWASP Mobile Application Security Verification Standard (MASVS) and the OWASP Mobile Application Security Testing Guide (MASTG). Two years of beta feedback produced 78 clearly defined organized as a consistently structured set of weaknesses across all eight MASVS domains. NowSecure Platform already maps findings to MASWE IDs today, so security and compliance teams using it don’t have to wait to put the new standard to work.

What Is OWASP MASWE v1.0?

The OWASP Mobile Application Security Weakness Enumeration (MASWE) catalogs the specific ways mobile apps go wrong on security and privacy. It sits between the two standards most security teams already know: Mobile Application Security Verification Standard (MASVS) defines the controls an app should meet and the Mobile Application Security Testing Guide (MASTG) defines the tests that verify them. MASWE fills the gap in between by naming the actual weakness a failed control points to.

MASWE has been in beta since mid-2024, and it showed. Of 119 draft entries, 89 were still placeholders, and the 30 that were finished had been written by different contributors over two years with no shared structure. Version 1.0.0 fixes that (see the full OWASP announcement). OWASP’s Mobile Application Security (MAS) Task Force consolidated the catalog down to 78 weaknesses, merging near-duplicates (nine separate “unsafe handling of data from X” entries became one weakness, for example), assigned stable, permanent IDs and gave every entry the same four-part structure: what the weakness is, how it gets introduced, what it costs the business if it’s exploited and how to fix it.

That consistency matters more than it sounds like it should. With MASTG v2.0’s release in June 2026, every test in the testing guide now links to a specific MASWE weakness, which links to a specific MASVS control. MASWE v1.0 is what makes that chain hold up end to end: MASVS control to MASWE weakness to MASTG test to MASTG demo.

Why Does OWASP MASWE Matter for Security and Compliance Teams?

For security leaders, the value isn’t the taxonomy itself. It’s what a stable taxonomy lets you do with it.

“The app failed MASVS-STORAGE-2” doesn’t give a developer anything to work with. But saying “The app failed MASWE-0005 because of verbose logging in production,” that’s a problem they can actually fix.

‘The app failed MASVS-STORAGE-2’ doesn’t give a developer anything to work with. But saying ‘The app failed MASWE-0005 because of verbose logging in production,’ that’s a problem they can actually fix.


That specificity is what turns a pentest report into something a developer can fix, an auditor can verify and a CISO can point to as evidence of due diligence, using a common vocabulary that means the same thing whether the finding came from an internal test, a third-party pen test or an automated scan.

MASVS and MASTG are already referenced by the App Defense Alliance (ADA) Mobile Application Security Assessment (MASA) program, CREST OVS and NIST SP 800-163r1 and SP 800-218, so ambiguity in the underlying standard becomes ambiguity in someone’s compliance obligation. A well-defined weakness enumeration is built to remove exactly that kind of ambiguity.

Does NowSecure Platform Support OWASP MASWE?

NowSecure has contributed to the OWASP MAS project since 2021, with Carlos Holguera, a NowSecure distinguished research engineer, serving as OWASP MAS project co-chair. OWASP credited Carlos in the MASWE v1.0 release notes for driving the remapping, the consolidation and the authoring standard that kept a catalog this size internally consistent. NowSecure is also named as one of OWASP MAS’s ongoing Advocates, the group of organizations OWASP recognized for sustained contribution to the project.

More practically for teams evaluating this today: NowSecure Platform already tags findings with their corresponding MASWE IDs, alongside the same findings’ MASVS, GDPR, HIPAA and PCI DSS mappings. A finding like “App Requests Dangerous Permissions” already shows up mapped to MASWE-0066 in the platform’s Regulatory tab.

APp Requests Dangerous Permissions image 1
MASWE-0066: Inadequate Permission Management image 2

Teams using NowSecure Platform for continuous or on-demand mobile app security testing benefit from the new standard without having to remap anything themselves.

Where to Go From Here

If your organization already treats MASVS as the bar for mobile app security, the MASWE v1.0 layer makes findings against that bar traceable and specific. It’s worth updating any internal scorecards or vendor requirements that currently cite only MASVS controls. 

For a primer on how MASVS, MASTG and MASWE fit together, see NowSecure’s Essential Guide to OWASP. Request a demo of NowSecure Platform to see MASWE-mapped findings on your own apps.