Mobile Banking Security Weekly #1

· Khoi Van

🔴 Critical Updates

ANDROID SECURITY BULLETIN · CRITICAL
System RCE vulnerability · SPL 2025-08-05
Update test devices immediately

GOOGLE PLAY API 35 · HIGH
Required by August 31, 2025
Extension available until November 1


🤖 Android

Security Bulletin · August 2025

CRITICAL SPL 2025-08-01/05

System RCE vulnerability and framework EoP. Pixel devices patched at 2025-08-05 level.

Impact: Login flows, OTP verification, 3DS authentication

Actions:

  • Update test devices to SPL 2025-08-05
  • Run smoke tests (login, transfers, 3DS)
  • Monitor crash rates for 48h post-update

Test Matrix: Android API 29-35 / WebView 139.x

Pixel Update Bulletin · August 2025

HIGH SPL 2025-08-05

Additional patches for Pixel devices including modem fixes.

Impact: Login flows, SMS/Voice OTP, 3DS authentication

Actions:

  • Update Pixel lab devices to 2025-08-05
  • Test SMS/Voice OTP after OTA
  • Monitor incident reports

Test Matrix: Android API 29-35 / WebView 139.x

Google Play API 35 Requirement

HIGH Deadline: August 31, 2025

Apps failing requirement will be blocked from submission/updates. Extension available until November 1.

Impact: Store submission, Build/Release pipeline

Actions:

  • Set targetSdkVersion=35
  • Update blocked dependencies (permissions/file access)
  • Run Android 15 compatibility tests
    • Predictive back gesture
    • Behavior changes

Test Matrix: Android 15 (API 35)

Android Studio Narwhal 2025.1.2

LOW Stable Release

New stable version for Android teams.

Optional Actions:

  • Standardize IDE/AGP version on CI
  • Sync/clean build
  • Review new AGP/lint warnings

Test Matrix: AGP/Gradle on CI


🍎 iOS

iOS/iPadOS 18.6.1 Security Update

MEDIUM Released: August 14, 2025

Latest security patch for iOS 18. CVEs not disclosed at release.

Impact: Login flows, OTP verification, 3DS authentication

Actions:

  • Update QA devices to 18.6.1
  • Run App Attest/DeviceCheck regression
  • Test WKWebView checkout performance

Test Matrix: iOS 18.6.1 / WKWebView 18.6.x


🌐 Cross-Platform

Flutter 3.35 Stable

LOW Released: August 13, 2025

New stable version. Consider upgrading cross-platform apps.

Optional Actions:

  • Check package breaking changes
  • Run flutter test on pipeline
  • Measure bundle size after upgrade

Test Matrix: Flutter 3.35 / Dart

React Native 0.79.x

LOW Branch 0.79

Bugfixes for 0.79 branch.

Optional Actions:

  • Review Android/iOS changelog
  • Run E2E Detox/QA flows
  • Check AGP/Xcode compatibility

Test Matrix: RN 0.79.x / Hermes


🛡️ Security & Tamper Detection

Frida 17.2.16

MEDIUM Released: August 12, 2025

Hook tool update. Adjust detection/hardening if RASP has version-specific rules.

Impact: RASP/Hook tamper detection

Actions:

  • Update Frida test rig to 17.2.16
  • Verify injection/ptrace detection rules
  • Test anti-hook at login/KYC screens

Test Matrix: Android 14-15 / iOS 17-18


👁️ Community Watchlist

⚠️ Unverified community reports - awaiting official confirmation

Play Integrity API Changes

VOZ Report #1: Play Integrity/Integrity Box free tier only returning BASIC after Play Store update

Banking App Detection Bypasses

VOZ Report #2: MBBank detection methods and bypasses

VOZ Report #3: Magisk alpha 302 issues

VOZ Report #4: VietinBank detection patterns


Next Week

  • Android 15 compatibility testing
  • Play Integrity API monitoring
  • iOS 18.7 beta evaluation

Mobile Banking Security Weekly #1 · August 17, 2025
Questions? Contact security@yourbank.com

Comments