OWASP’s MASWE v1 and MASTG v2 give mobile app security teams more consistent ways to describe weaknesses and test Android and iOS apps. In a recent webinar, NowSecure Distinguished Research Engineer and OWASP MAS project co-chair Carlos Holguera walked through the updates with OWASP Foundation Director of Open Source Projects and Programs Starr Brown.
Here’s how to use the updated framework to define security requirements, select relevant tests and report findings as part of a mobile application risk management program.
What Changed in MASWE v1 & MASTG v2?
We’ve already covered the releases themselves: MASTG v2 shipped in June and MASWE hit v1.0 in August, consolidating 119 beta weaknesses into 78. MASWE also added or revised six weakness entries covering accessibility, malicious code, jailbreak and root detection, malware detection, functionality that fails to preserve privacy and non-reproducible builds.
The webinar explained the reasoning behind those decisions and demonstrated how teams can use the updated OWASP resources in their daily work.
How Do MASVS, MASWE and MASTG Work Together?
OWASP MAS connects three resources for mobile app security testing:
- The Mobile Application Security Verification Standard (MASVS) defines security and privacy controls.
- The Mobile Application Security Weakness Enumeration (MASWE) describes weaknesses that can undermine those controls.
- The Mobile Application Security Testing Guide (MASTG) explains how to test for those weaknesses on Android and iOS.
MASVS sets high-level controls, such as avoiding weak cryptography. MASWE breaks those controls into specific weaknesses an app can have, while MASTG provides platform-specific testing instructions.

Holguera said the goal behind MASWE’s consolidation is a catalog that holds up over time: “We want to make the MASWE something that scales, that is future-proof.” A stable weakness ID can remain useful even as platform APIs and the tests behind it evolve.
We want to make the MASWE something that scales, that is future-proof.
MASTG v2 went through a similar restructuring. Where the old guide repeated instructions such as installing Frida across multiple tests, the updated guide isolates those instructions as reusable techniques. Individual, focused tests reference those techniques.
Runnable demos make the guidance easier to apply. Built on “skeleton apps,” these minimal Android or iOS projects contain the code pattern being tested. The demos provide sample code and downloadable APKs or IPAs, with test scripts and outputs that help testers reproduce the results. Teams can also modify the sample code to explore different implementations.
At the time of the webinar, MASWE contained 78 weaknesses, while MASTG provided roughly 200 v2 tests, 140 knowledge articles, 170 techniques, 140 tools and 160 demos. Holguera noted that community contributions expand these resources daily.
How to Use OWASP Standards for Mobile AppSec Testing
Holguera recommended starting with MASVS for an overview. Its eight categories—storage, cryptography, authentication, network, platform, code, resilience and privacy—help teams identify familiar topics and areas that need more attention. From there, use the corresponding MASWE categories to find weaknesses relevant to your app.
Two additions to MASWE v1 support this work. Each entry now uses standardized impact language, giving teams a consistent starting point for explaining risk. Each also includes a requirement statement that developers and security teams can use during threat modeling and design.
For example, a team can use the requirement to exclude sensitive data from application logs during design, then follow the linked MASTG tests to check the implementation.
OWASP also expanded MASWE’s mappings to connect weaknesses with relevant MASVS controls, CWE entries and Google’s Android security and privacy documentation. Those Android references help developers connect findings to guidance they already use.
Choose a Testing Profile That Fits Your App
Not every weakness applies to every app. OWASP MAS Testing Profiles help teams select controls and tests appropriate to an app’s functionality, data and risks. L1 covers essential security, L2 covers advanced security and R addresses resilience against reverse engineering and tampering. A separate P profile covers baseline privacy.
Holguera used a weather app to illustrate why context matters. An app that collects location data needs protections that may not apply to an app without that functionality.
Teams should tailor their testing scope to the app and document why particular weaknesses do not apply. The profile provides a starting point; the app’s specific risks determine which checks it needs.
Map Findings to MASWE & Add Context
For penetration testers, Holguera recommended mapping each finding to a MASWE ID, using the standardized language as a foundation and then adding the specifics of the app under review.
That context matters. A weakness classification gives teams a shared reference, while the finding needs to explain how the weakness appears in the app and what it means for that application.
Holguera also acknowledged feedback that MASTG does not always follow a typical penetration testing workflow. He encouraged testers to share gaps or suggestions through OWASP’s GitHub, Slack or website.
The Experts Behind OWASP MAS
These updates draw on the MAS Task Force, a group of industry experts who regularly review pull requests and debate proposed additions. The MAS Advocates program also recognizes companies and individuals who contribute consistently. NowSecure participates as an advocate and contributor.
The community expanded its opportunities to exchange knowledge this year with the first OWASP MAScon in Vienna. Embedded within OWASP Global AppSec EU, the event brought together mobile security practitioners, including attendees who traveled specifically for the mobile security sessions.
Put OWASP MAS into Practice with NowSecure
Teams already using MASVS can start by reviewing their testing scope against the updated MASWE catalog, choosing a profile that reflects their apps’ risks and using the linked MASTG tests to investigate relevant weaknesses. Each finding should connect the standardized weakness description to the app’s specific behavior and potential impact.
NowSecure contributed 320 pull requests to help ship MASTG v2, and NowSecure Platform already maps findings to MASWE v1, helping teams apply the framework within their existing testing workflow.
The value comes from carrying those connections through development: a security requirement informs implementation, a test checks whether the protection works and a finding gives developers the context to fix what falls short. The updated OWASP MAS resources make that process easier to repeat with each release.
Want to see how it works? Watch the webinar replay with OWASP MAS project co-chair Carlos Holguera and OWASP’s Starr Brown for a walkthrough of MASWE v1, MASTG v2 and how to apply them to your mobile app risk management program.

