Research & Threat Intel
An attacker can exploit iOS WebViews to make automatic calls to an attacker-controlled phone number OR FaceTime address. Our research has found that FaceTime URL (facetime://) handlers are frequently overlooked in iOS applications. The oversight allows an attacker to potentially capture a video or snapshot of the affected user by directing them to a webpage from within a vulnerable WebView.
A blog post providing an introduction on how to use Radare for Android malware analysis. After reading this post, you’ll understand how to use Radare2 to disassemble Android binaries, how to identify suspicious or malicious app behavior, and some of the benefits and limitations of using Radare2 for this use case.
The Android Vulnerability Test Suite lets Android users test their devices for security issues.
The new Frida 6.0 includes many exciting functionalities.
Security analysts typically rely on their development team to export an .ipa file for security testing iOS apps. This post provides step-by-step instructions for using Xcode to export an app for security testing purposes.
Learn more about the OnePlus device backdoor created by the EngineerMode App and how the NowSecure Threat Research Team helped verify this root exploit.
If you’ve ever tried to compile DVIA for iOS 10 and Xcode 8, you probably ran into some challenges. This article teaches you step-by-step how to compile DVIA for mobile app security testing.
The Dirty COW vulnerability impacts many mobile devices. I analyzed it and its exploit and ended up writing a plug-in for Radare2.
Samsung Galaxy S3 can be triggered via an injected frame, QR code, Near Field Communications, or SMS text message
Issues associated with many apps’ CEVs.