M6:2024: Inadequate Privacy Controls
Collection, retention, or third-party sharing of personal data beyond what the app discloses to the user, including data harvested by embedded SDKs.
How it's found
Detected by reviewing the app's data collection and third-party SDK traffic for personal-data exposure beyond what the app discloses.
Standards mapping
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Exposure of Sensitive Information to an Unauthorized Actor using Vuln Scanner's exposure templates (exposed configuration files, admin panels, API keys, .env and .git paths), with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 8 dedicated rules for this weakness. For AI/LLM targets, Paladin AI additionally probes model responses for sensitive-information disclosure, such as leaked system prompts, training-data fragments, or credentials surfaced in generated output.
Tools: Vuln Scanner, Paladin AI
Frequently asked questions
What is M6:2024 Inadequate Privacy Controls?
Collection, retention, or third-party sharing of personal data beyond what the app discloses to the user, including data harvested by embedded SDKs.
How do you find Inadequate Privacy Controls?
Detected by reviewing the app's data collection and third-party SDK traffic for personal-data exposure beyond what the app discloses.
Which CWEs map to M6:2024?
M6:2024 maps to CWE-200, CWE-359.
Does TurboPentest test for Inadequate Privacy Controls?
TurboPentest's automated black-box pentest actively probes for Exposure of Sensitive Information to an Unauthorized Actor using Vuln Scanner's exposure templates (exposed configuration files, admin panels, API keys, .env and .git paths), with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 8 dedicated rules for this weakness. For AI/LLM targets, Paladin AI additionally probes model responses for sensitive-information disclosure, such as leaked system prompts, training-data fragments, or credentials surfaced in generated output.
Related OWASP categories
- OWASP Mobile Top 10M1:2024: Improper Credential Usage
- OWASP Mobile Top 10M2:2024: Inadequate Supply Chain Security
- OWASP Mobile Top 10M3:2024: Insecure Authentication/Authorization
- OWASP Mobile Top 10M4:2024: Insufficient Input/Output Validation
- OWASP Mobile Top 10M5:2024: Insecure Communication
- OWASP Mobile Top 10M7:2024: Insufficient Binary Protections
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest