Skip to content
June 30, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • Technique
  • Pitfalls of developing mobile banking application
  • Technique

Pitfalls of developing mobile banking application

Do Son April 23, 2021 3 minutes read

There is an active development of mobile technologies. The modern business requirements are such that access to information should be carried out quickly, reliably, and from anywhere in the world. Payment apps are no exception. And they are gradually appearing on our mobile devices (smartphones, tablets, etc.). Mobile devices have not yet been sufficiently studied. And each mobile OS (Android, iOS, Windows Phone, Symbian, BlackBerry, etc.) has its own specifics. So in each of them, you can find a large number of both new vulnerabilities and well-known ones. Experienced mobile banking app developers always take this into consideration.

Types of mobile banking apps

The “no account access” category includes programs that perform only auxiliary work. These functions may also be present in applications that have the ability to work with an account. Often a mobile application evolves from a simple navigation application to an account-based application. Some banks, on the contrary, prefer to distribute these functions to several applications. From the main point of view, it is correct. If a critical application is not overloaded with unnecessary functionality, the number of attack vectors available to an attacker decreases.

Main disadvantages

As you can see, there are plenty of advantages of mobile banking. But you shouldn’t give in to the illusion of impeccability. The fact is that there are many factors that limit the rapid growth of financial and mobile technologies. Today, many banks are actively developing this area of ​​activity, but many problems remain open.

For example, the following problems of Mobile Banking can be highlighted:

  1. Organizational and legislative base. It is planned that during the formation of this structure, all those who take part in the mobile banking market will be centralized. These structures, according to the announced plans, will take over the function of exercising control over mobile payments, which include mobile banking;
  2. Low acceptance in the banking environment. Despite the improvement of mobile technologies, they are very skeptical about the mobile banking segment. Nevertheless, 80% of banks provide mobile banking services. But customers only get access to limited functionality. That is, most of the useful functions are unreasonably cut. However, recently, many banking organizations, realizing the prospects and need for a mobile bank, are gradually expanding the capabilities of their service systems;
  3. Technological backwardness. For example, only a few banks provide full-fledged mobile banking for iPhone, iPad and Android.
  4. Security guarantees. No matter what efforts are made by information security specialists, the “holes” both exist and will continue to exist. And the main problem is not in the protection systems. And the fact is that in most cases, threats arise through the fault of the clients themselves. It often does not realize the risks from its own actions. That is, users simply do not know how to use the mobile bank correctly. It is planned that in the future such problems will be eliminated through the development of systems. They are used for scanning the face of the owner of a mobile device, fingerprints, voice recognition, etc. All this will be, but it will take time and money. Since the use of such technologies is possible only on modern devices, which can also cost a lot of money.

Each mobile OS has its own specifics, and each of them contains a large number of both new and well-known vulnerabilities. And while developing a mobile banking application these details must be considered.

Share this article:

Facebook Post LinkedIn Telegram

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🚨 Active Exploits in the Wild

  • CVE-2026-48558CVSS 10.0
    SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication...
    Admin intelCISA KEV📅 Added to KEV: Jun 29, 2026📅 Updated: Jun 29, 2026
  • CVE-2026-46817CVSS 9.8
    Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected...
    Admin intel📅 Updated: Jun 29, 2026
  • CVE-2026-28496CVSS 9.4
    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template...
    Admin intel📅 Updated: Jun 25, 2026
  • CVE-2026-12569
    A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The...
    CISA KEV📅 Added to KEV: Jun 25, 2026
  • CVE-2025-67038CVSS 9.8
    An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write...
    CISA KEV📅 Added to KEV: Jun 23, 2026
  • CVE-2026-34908CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi...
    CISA KEV📅 Added to KEV: Jun 23, 2026
  • CVE-2026-34909CVSS 10.0
    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS...
    CISA KEV📅 Added to KEV: Jun 23, 2026
  • CVE-2026-34910CVSS 10.0
    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi...
    CISA KEV📅 Added to KEV: Jun 23, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-8402CVSS 9.8
    Improper neutralization of special elements used in an SQL command ('SQL injection')...
  • CVE-2026-14162CVSS 9.8
    Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability,...
  • CVE-2026-9711CVSS 9.8
    The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full)...
  • CVE-2026-12073CVSS 9.8
    The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is...
  • CVE-2026-57498CVSS 9.6
    Coolify is an open-source and self-hostable tool for managing servers, applications, and...
  • CVE-2026-37637CVSS 9.1
    An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute...
  • CVE-2026-13763CVSS 9.8
    Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS...
  • CVE-2026-13762CVSS 9.8
    Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled...
  • CVE-2026-56782CVSS 9.8
    Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and...
  • CVE-2026-57331CVSS 9.9
    Performer Arbitrary File Deletion in Paid Videochat Turnkey Site
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.