<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerabilities :: DVMA - Damn Vulnerable Mobile App</title><link>https://cpeoples.github.io/dvma/vulnerabilities/index.html</link><description>Every DVMA vulnerability by OWASP MASVS category, mapped to the OWASP Mobile Top 10, MASVS/MASTG, CWE, and the LLM/Agentic Top 10.</description><generator>Hugo</generator><language>en</language><lastBuildDate>Thu, 24 Sep 2026 16:36:55 +0000</lastBuildDate><atom:link href="https://cpeoples.github.io/dvma/vulnerabilities/index.xml" rel="self" type="application/rss+xml"/><item><title>Insecure Data Storage</title><link>https://cpeoples.github.io/dvma/vulnerabilities/storage/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/storage/index.html</guid><description>Sensitive data persisted without protection: plaintext key-value stores, misused Keychain/Keystore, backup leakage, clipboard, screenshots, logs, keyboard…</description></item><item><title>Insufficient Cryptography</title><link>https://cpeoples.github.io/dvma/vulnerabilities/crypto/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/crypto/index.html</guid><description>Weak algorithms, hardcoded keys and static IVs, insecure randomness, trivial key derivation, and homegrown 'encryption'.</description></item><item><title>Insecure Authentication / Authorization</title><link>https://cpeoples.github.io/dvma/vulnerabilities/auth/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/auth/index.html</guid><description>Sessions that never expire or use predictable tokens, bypassable biometrics, weak password policy, client-side-only authorization, JWT alg:none / weak secrets…</description></item><item><title>Insecure Communication</title><link>https://cpeoples.github.io/dvma/vulnerabilities/network/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/network/index.html</guid><description>Cleartext traffic, weak TLS, bypassable pinning, accept-all trust managers, and WebViews that ignore network security config.</description></item><item><title>Improper Platform Usage</title><link>https://cpeoples.github.io/dvma/vulnerabilities/platform/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/platform/index.html</guid><description>WebView JS-bridge RCE and file:// access, deep-link/URL-scheme hijack, exported components, content-provider SQLi, pending-intent hijack, tapjacking…</description></item><item><title>Code Quality &amp; Build Config</title><link>https://cpeoples.github.io/dvma/vulnerabilities/code_quality/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/code_quality/index.html</guid><description>Debuggable release builds, no obfuscation, verbose error handling that leaks stack traces, a bundled dependency with a known CVE, and an optional native…</description></item><item><title>Insufficient Resilience</title><link>https://cpeoples.github.io/dvma/vulnerabilities/resilience/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/resilience/index.html</guid><description>Root/jailbreak, anti-debugging, integrity/tamper, emulator, and Frida detection that are all trivially bypassable, plus a TOCTOU race in auth.</description></item><item><title>Supply Chain (OWASP Mobile M2)</title><link>https://cpeoples.github.io/dvma/vulnerabilities/supply_chain/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/supply_chain/index.html</guid><description>A maliciously-behaving bundled SDK, a typosquatted-package scenario, and a build artifact with no signing/integrity verification.</description></item><item><title>Privacy (OWASP Mobile M6)</title><link>https://cpeoples.github.io/dvma/vulnerabilities/privacy/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/privacy/index.html</guid><description>Data accessed with no consent screen, no tracking-transparency prompt, and PII flowing into analytics unfiltered.</description></item><item><title>Input Validation (OWASP Mobile M4)</title><link>https://cpeoples.github.io/dvma/vulnerabilities/input_validation/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/input_validation/index.html</guid><description>Unsafe deserialization of untrusted data, and Intent extras trusted without validation leading to privilege escalation.</description></item><item><title>AI/ML (OWASP LLM/GenAI Top 10)</title><link>https://cpeoples.github.io/dvma/vulnerabilities/ai_ml/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/ai_ml/index.html</guid><description>An in-app AI assistant demonstrating the OWASP Top 10 for LLM/GenAI, adapted to a mobile client: prompt injection (direct + indirect), insecure output…</description></item><item><title>Agentic AI (OWASP Agentic Top 10)</title><link>https://cpeoples.github.io/dvma/vulnerabilities/agentic/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/agentic/index.html</guid><description>An in-app AI *agent* with persistent memory, tool/MCP-style connectors, and sub-agents. Demonstrates the OWASP Top 10 for Agentic AI Applications (2025)…</description></item><item><title>AI + Mobile (LLM x IPC / WebView)</title><link>https://cpeoples.github.io/dvma/vulnerabilities/ai_mobile/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/ai_mobile/index.html</guid><description>The emerging crossover surface where an on-device AI assistant meets classic mobile trust boundaries: untrusted mobile input (deep links, clipboard, QR…</description></item><item><title>Native / WebView Bridge (JS &lt;-&gt; Native)</title><link>https://cpeoples.github.io/dvma/vulnerabilities/native_bridge/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/native_bridge/index.html</guid><description>The WebView&lt;-&gt;native JavaScript bridge as its own cross-platform trust boundary (Android addJavascriptInterface / WebMessageListener; iOS…</description></item><item><title>Privileged System-Provider Activation</title><link>https://cpeoples.github.io/dvma/vulnerabilities/system_provider/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/system_provider/index.html</guid><description>Mobile Capability Broker Abuse: the umbrella surface where an app becomes a privileged system actor/provider and therefore a broker between an untrusted actor…</description></item><item><title>Detail</title><link>https://cpeoples.github.io/dvma/vulnerabilities/detail/index.html</link><pubDate>Thu, 24 Sep 2026 16:36:55 +0000</pubDate><guid>https://cpeoples.github.io/dvma/vulnerabilities/detail/index.html</guid><description>Per-vulnerability detail pages.</description></item></channel></rss>