Synopsys Research Reveals Significant Security Concerns in Popular Mobile Apps Amid Pandemic
Synopsys, Inc. (Nasdaq: SNPS) released a report highlighting significant security vulnerabilities in popular mobile apps, revealing that 63% of 3,335 analyzed apps contained open source components with known vulnerabilities. The report, produced by the Synopsys Cybersecurity Research Center, indicates an average of 39 vulnerabilities per vulnerable app, with over 3,000 unique vulnerabilities identified. Notably, 94% of these vulnerabilities have documented fixes. The analysis underscores a critical need for improved mobile app security due to increased reliance on mobile apps during the pandemic.
- 94% of detected vulnerabilities have documented fixes.
- Increasing demand for mobile app security solutions amid pandemic.
- 63% of analyzed apps contained known vulnerabilities.
- Average of 39 vulnerabilities per vulnerable app.
- 43% of vulnerabilities are classified as high risk.
- Significant information leakage found in applications.
MOUNTAIN VIEW, Calif., March 25, 2021 /PRNewswire/ -- Synopsys, Inc. (Nasdaq: SNPS) today released the report, Peril in a Pandemic: The State of Mobile Application Security Testing. The report, produced by the Synopsys Cybersecurity Research Center (CyRC), examines the results of a study of the 3,335 most popular Android mobile apps on the Google Play Store in the first quarter on 2021. The report found the majority of apps (
The research, which was conducted using Synopsys Black Duck Binary Analysis1, focused on 18 popular mobile app categories, many of which have seen explosive growth during the pandemic, including business, education, and health & fitness. The apps ranked among the most downloaded or top grossing on the Google Play Store. While the security analysis results vary by app category, at least one-third of the apps in all 18 categories contained known security vulnerabilities.
"Like any other software, mobile apps are not immune to security weaknesses and vulnerabilities that can put consumers and businesses at risk," said Jason Schmitt, general manager of the Synopsys Software Integrity Group. "Today, mobile app security is especially important when you consider how the pandemic has forced many of us—including children, students, and large portions of the workforce—to adapt to increasingly mobile-dependent, remote lifestyles. Against the backdrop of these changes, this report underscores the critical need for the mobile app ecosystem to collectively raise the bar for developing and maintaining secure software."
Open source vulnerabilities in mobile apps are pervasive. Out of the 3,335 apps analyzed,
Known vulnerabilities are a solvable problem. While the number of vulnerabilities uncovered in this research is daunting, it is perhaps more surprising that
In-depth analysis of high-risk vulnerabilities. A more thorough analysis revealed that nearly half (
Information leakage. When developers unintentionally expose sensitive or personal data in the source code or configuration files of an application, it can potentially be used by malicious attackers to mount subsequent attacks. CyRC found tens of thousands of instances of information leakage, where potentially sensitive information was exposed, ranging from private keys and tokens to email and IP addresses.
Excessive use of mobile device permissions. Mobile apps often require access to certain features or data from your mobile device to function effectively. However, some apps recklessly or surreptitiously require far more access than necessary. The mobile apps analyzed by CyRC require an average of 18 device permissions. That includes an average of 4.5 sensitive permissions, or those that require the most access to personal data, and an average of 3 permissions that Google classifies as "not intended for third-party use." One app with over 1 million downloads required 11 permissions that Google classifies as "Protection Level: Dangerous." Another app with over 5 million downloads required a total of 56 permissions, 31 of which Google classifies as "Protection Level: Dangerous" or as signature permissions that are not to be used by third-party apps.
Comparing app categories. At least
To learn more, download the report, Peril in a Pandemic: The State of Mobile Application Security Testing.
1. Black Duck Binary Analysis is a unique feature of the Black Duck software composition analysis offering that can be used to detect security vulnerabilities, information leakage and mobile device permissions in software. Unlike most other software analysis tools, it analyzes compiled binaries instead of source code, meaning it can scan virtually any software, from desktop and mobile applications to embedded system firmware. To learn more, watch the Black Duck Binary Analysis webinar.
About the Synopsys Software Integrity Group
Synopsys Software Integrity Group helps development teams build secure, high-quality software, minimizing risks while maximizing speed and productivity. Synopsys, a recognized leader in application security, provides static analysis, software composition analysis, and dynamic analysis solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Synopsys helps organizations optimize security and quality in DevSecOps and throughout the software development life cycle. Learn more at www.synopsys.com/software.
About Synopsys
Synopsys, Inc. (Nasdaq: SNPS) is the Silicon to Software™ partner for innovative companies developing the electronic products and software applications we rely on every day. As an S&P 500 company, Synopsys has a long history of being a global leader in electronic design automation (EDA) and semiconductor IP and offers the industry's broadest portfolio of application security testing tools and services. Whether you're a system-on-chip (SoC) designer creating advanced semiconductors, or a software developer writing more secure, high-quality code, Synopsys has the solutions needed to deliver innovative products. Learn more at www.synopsys.com.
Editorial Contacts:
Mark Van Elderen
Synopsys, Inc.
650-793-7450
mark.vanelderen@synopsys.com
View original content:http://www.prnewswire.com/news-releases/synopsys-research-reveals-significant-security-concerns-in-popular-mobile-apps-amid-pandemic-301255891.html
SOURCE Synopsys, Inc.
FAQ
What did Synopsys report on March 25, 2021?
What percentage of mobile apps analyzed contained security vulnerabilities?
How many unique vulnerabilities were identified in the Synopsys report?
What risks are associated with the vulnerabilities in mobile apps?