Skip to content
July 20, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • Pitfalls of developing mobile banking application
  • Technique

Pitfalls of developing mobile banking application

Do Son April 23, 2021 3 minutes read

There is an active development of mobile technologies. The modern business requirements are such that access to information should be carried out quickly, reliably, and from anywhere in the world. Payment apps are no exception. And they are gradually appearing on our mobile devices (smartphones, tablets, etc.). Mobile devices have not yet been sufficiently studied. And each mobile OS (Android, iOS, Windows Phone, Symbian, BlackBerry, etc.) has its own specifics. So in each of them, you can find a large number of both new vulnerabilities and well-known ones. Experienced mobile banking app developers always take this into consideration.

Types of mobile banking apps

The “no account access” category includes programs that perform only auxiliary work. These functions may also be present in applications that have the ability to work with an account. Often a mobile application evolves from a simple navigation application to an account-based application. Some banks, on the contrary, prefer to distribute these functions to several applications. From the main point of view, it is correct. If a critical application is not overloaded with unnecessary functionality, the number of attack vectors available to an attacker decreases.

Main disadvantages

As you can see, there are plenty of advantages of mobile banking. But you shouldn’t give in to the illusion of impeccability. The fact is that there are many factors that limit the rapid growth of financial and mobile technologies. Today, many banks are actively developing this area of ​​activity, but many problems remain open.

For example, the following problems of Mobile Banking can be highlighted:

  1. Organizational and legislative base. It is planned that during the formation of this structure, all those who take part in the mobile banking market will be centralized. These structures, according to the announced plans, will take over the function of exercising control over mobile payments, which include mobile banking;
  2. Low acceptance in the banking environment. Despite the improvement of mobile technologies, they are very skeptical about the mobile banking segment. Nevertheless, 80% of banks provide mobile banking services. But customers only get access to limited functionality. That is, most of the useful functions are unreasonably cut. However, recently, many banking organizations, realizing the prospects and need for a mobile bank, are gradually expanding the capabilities of their service systems;
  3. Technological backwardness. For example, only a few banks provide full-fledged mobile banking for iPhone, iPad and Android.
  4. Security guarantees. No matter what efforts are made by information security specialists, the “holes” both exist and will continue to exist. And the main problem is not in the protection systems. And the fact is that in most cases, threats arise through the fault of the clients themselves. It often does not realize the risks from its own actions. That is, users simply do not know how to use the mobile bank correctly. It is planned that in the future such problems will be eliminated through the development of systems. They are used for scanning the face of the owner of a mobile device, fingerprints, voice recognition, etc. All this will be, but it will take time and money. Since the use of such technologies is possible only on modern devices, which can also cost a lot of money.

Each mobile OS has its own specifics, and each of them contains a large number of both new and well-known vulnerabilities. And while developing a mobile banking application these details must be considered.

Share this article:

Facebook Post LinkedIn Telegram

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-6875CVSS 9.5
    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability...
    Admin intel📅 Updated: Jul 18, 2026
  • CVE-2026-39808CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-25089CVSS 9.8
    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox...
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2026-58644CVSS 9.8
    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    CISA KEV📅 Added to KEV: Jul 16, 2026
  • CVE-2023-4346CVSS 7.5
    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to...
    CISA KEV📅 Added to KEV: Jul 15, 2026
  • CVE-2026-53362
    In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation...
    Admin intel📅 Updated: Jul 14, 2026
  • CVE-2026-46242CVSS 7.8
    In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file...
    Admin intel📅 Updated: Jul 14, 2026
  • CVE-2026-56155CVSS 7.8
    Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate...
    CISA KEV📅 Added to KEV: Jul 14, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-39878CVSS 9.3
    Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability...
  • CVE-2026-54051CVSS 9.9
    Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent...
  • CVE-2026-41252CVSS 9.8
    xrdp is an open source RDP server. Versions 0.10.6 and prior contain...
  • CVE-2026-35048CVSS 9.8
    The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for...
  • CVE-2026-51027CVSS 9.9
    An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive...
  • CVE-2026-46412CVSS 10.0
    @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with...
  • CVE-2026-35198CVSS 9.0
    HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored...
  • CVE-2026-12701CVSS 9.0
    A path traversal vulnerability was found in pulpcore. The relative_path_validator function only...
  • CVE-2026-64620CVSS 9.8
    FreeRDP before 3.28.0 (affected
  • CVE-2026-16242CVSS 9.4
    A flaw was found in the Konnectivity proxy-server configuration for hosted control...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.