1. DVMA > 
  2. Vulnerabilities > 
  3. Supply Chain (OWASP Mobile M2)

Supply Chain (OWASP Mobile M2)

A maliciously-behaving bundled SDK, a typosquatted-package scenario, and a build artifact with no signing/integrity verification.

8 vulnerabilities. OWASP Mobile: M2

VulnerabilityIDPlatformDifficultyOWASPMASVSMASWEMASTG (v2)CWE
Missing / Stale SBOM (No Component Inventory)sbom_missing_or_staleAndroidiOSEASYM2MASVS-CODE-3MASVS-CODE-1MASWE-0044MASTG-TEST-0274MASTG-TEST-0275CWE-1104CWE-1035
Typosquatted Dependencytyposquatted_dependencyAndroidiOSEASYM2MASVS-CODE-3MASWE-0048MASTG-TEST-0272MASTG-TEST-0273CWE-829CWE-427
Insecure Firebase / Cloud Backend Configinsecure_firebase_cloud_configAndroidiOSMEDIUMM8MASVS-STORAGE-2MASVS-NETWORK-1MASVS-CODE-2MASWE-0002MASTG-TEST-0212MASTG-TEST-0214CWE-1188CWE-668CWE-798
Malicious Third-Party SDKmalicious_third_party_sdkAndroidiOSMEDIUMM2MASVS-CODE-3MASVS-PRIVACY-1MASWE-0048MASTG-TEST-0318MASTG-TEST-0319CWE-506CWE-829
Unsigned / Unverified Build Artifactunsigned_unverified_build_artifactAndroidiOSMEDIUMM2MASVS-RESILIENCE-3MASVS-CODE-1MASWE-0057-CWE-347CWE-494
Dependency Confusion / Substitutiondependency_confusionAndroidiOSHARDM2MASVS-CODE-3MASVS-CODE-1MASWE-0048-CWE-427CWE-1357CWE-494
Bundled SDK Ships a Vulnerable Exported Componentsdk_exported_component_redirectionAndroidiOSHARDM2MASVS-CODE-3MASVS-PLATFORM-1MASWE-0032MASTG-TEST-0364MASTG-TEST-0372CWE-926CWE-749CWE-829
Silent SDK Auto-Update (Post-Deploy Behavior Change)silent_sdk_auto_updateAndroidiOSHARDM2MASVS-CODE-3MASVS-CODE-4MASWE-0043-CWE-494CWE-829
Sep 24, 2026
DVMA DVMA - Damn Vulnerable Mobile App

  • Home


    • Getting Started
      • Prerequisites
      • Installing Flutter
      • Android
      • iOS
      • Build & Flavors
      • Automation
      • CI & Releases
      • Contributing
    • Architecture
      • Native Bridges
      • Companion Attacker
      • The Real-Artifact Guarantee
    • Dashboard
    • Vulnerabilities
      • Insecure Data Storage
      • Insufficient Cryptography
      • Insecure Authentication / Authorization
      • Insecure Communication
      • Improper Platform Usage
      • Code Quality & Build Config
      • Insufficient Resilience
      • Supply Chain (OWASP Mobile M2)
      • Privacy (OWASP Mobile M6)
      • Input Validation (OWASP Mobile M4)
      • AI/ML (OWASP LLM/GenAI Top 10)
      • Agentic AI (OWASP Agentic Top 10)
      • AI + Mobile (LLM x IPC / WebView)
      • Native / WebView Bridge (JS <-> Native)
      • Privileged System-Provider Activation
    • Root & Jailbreak
      • Android
        • Root with Magisk
        • Autonomous script
        • Recover a bricked device
        • Verify artifacts
      • iOS
        • Download Dopamine
        • Install Dopamine
        • Run the jailbreak
        • palera1n (A8–A11)
        • Verify artifacts
    • Manual Testing
      • Android
      • iOS
    • GitHub Repo
    • OWASP MASVS

    •  

    Built with by Hugo