A security analysis of 107 banking apps released March 25 has found security flaws in 88 percent of the apps — some of which might be avoided through automation.

The mobile banking apps were among the 3,335 of the most popular free and paid Android apps on the Google Play Store that were downloaded and analyzed for the March 25 survey by the Synopsys Cybersecurity Research Center, the research arm of the security vendor Synopsys.
“One of the surprises for us was that, in the banking category, they were running above average in terms of known vulnerabilities and components and permissions they asked for,” Jonathan Knudsen, a senior security strategist for Synopsys, told Bank Automation News.
The survey looked at each app for known security vulnerabilities, at-risk components, and to what extent the app asked for access to different components of a cell phone, said Knudson. The study found that 94 of the 107 banking apps scanned, 88 percent, contained vulnerabilities that can create a range of problems; some simply cause an app to crash while others expose users to potential data theft.
“One of the surprises for us was that, in the banking category, they were running above average in terms of known vulnerabilities and components and permissions they asked for,” Knudsen said. While Synopsys declined to say which banking apps they’d analyzed, many major banks and neobanks host popular mobile apps on Google Play, including JPMorgan Chase, US Bank, PNC, Wells Fargo, Citi, Discover and Varo Money.
The survey also looked at open-source components used in the mobile apps. It found banking apps used on average 26.4 open-source components, compared to 27.8 for the top free games, 29.9 for the top grossing games, 24.3 percent for budget apps, and 21 percent for payment apps. That’s not necessarily a problem, Knudsen said, if correctly managed.
“There’s a ton of good stuff available, but you have to manage it properly … The problem is if you’ve written an app, and one of the components you used ends up with a vulnerability,” Knudson said. “You have to know about it somehow, so that you can respond and update your app to include the new version of the component.”
However, an automated solution exists for flawed code: A software composition analysis (SCA) tool, which can automatically detect vulnerabilities and open source licensing issues as developers code and after deployment.
Other security concerns that chief information officers, chief information security officers and developers should be aware of are related to the breadth of cell phone access that mobile banking apps request from a cell phone and hidden information in the final code, which creates security risks for customers.
“The upshot is, if you’re trying to be careful about security, your app should ask for the least number of permissions that it actually needs to function so that it doesn’t have access to more stuff on your phone than it should,” Knudsen said.
LexisNexis Risk Solutions’ semiannual cybersecurity report for the last half of 2020 corroborates the rise in attacks on mobile apps. Kimberly Sutherland, the data and analytics company’s vice president of fraud and identity strategy, told BAN that as more activity goes mobile, so will the fraudsters.
“We’re seeing a real strong adoption of mobile apps overall, and that’s really great, but that also means that fraudsters are going to drive there as well,” Sutherland said.
Bank Automation Ignite, on April 13-14, is the event for inspiring automation initiatives and investment in financial services. At the virtual event, financial services professionals can discover new use cases and technologies that are accelerating automation in banking. Learn more and register at www.BankAutomationIgnite.com.


