M2:2024: Inadequate Supply Chain Security
Vulnerable or tampered third-party SDKs, libraries, and build tooling pulled into the mobile app, plus insecure build/release pipelines that let a compromised dependency reach production.
How it's found
Detected by inspecting the app's third-party SDKs and build pipeline for known-vulnerable or tampered components.
Standards mapping
How TurboPentest tests for this (white-box)
Reliance on an Insufficiently Trustworthy Component is partly caught by white-box software composition analysis when you connect a GitHub repo: Dep Scanner (SCA) flags dependencies that carry known vulnerabilities or are outdated. Assessing the full trustworthiness of the supply chain, including build systems and package provenance, benefits from a manual IntegSec engagement with deeper methodology.
Tools: Dep Scanner
Frequently asked questions
What is M2:2024 Inadequate Supply Chain Security?
Vulnerable or tampered third-party SDKs, libraries, and build tooling pulled into the mobile app, plus insecure build/release pipelines that let a compromised dependency reach production.
How do you find Inadequate Supply Chain Security?
Detected by inspecting the app's third-party SDKs and build pipeline for known-vulnerable or tampered components.
Which CWEs map to M2:2024?
M2:2024 maps to CWE-1357, CWE-829, CWE-494.
Does TurboPentest test for Inadequate Supply Chain Security?
Reliance on an Insufficiently Trustworthy Component is partly caught by white-box software composition analysis when you connect a GitHub repo: Dep Scanner (SCA) flags dependencies that carry known vulnerabilities or are outdated. Assessing the full trustworthiness of the supply chain, including build systems and package provenance, benefits from a manual IntegSec engagement with deeper methodology.
Related OWASP categories
- OWASP Mobile Top 10M1:2024: Improper Credential Usage
- OWASP Mobile Top 10M3:2024: Insecure Authentication/Authorization
- OWASP Mobile Top 10M4:2024: Insufficient Input/Output Validation
- OWASP Mobile Top 10M5:2024: Insecure Communication
- OWASP Mobile Top 10M6:2024: Inadequate Privacy Controls
- OWASP Mobile Top 10M7:2024: Insufficient Binary Protections
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest