M6:2024: Inadequate Privacy Controls
Collection, retention, or third-party sharing of personal data beyond what the app discloses to the user, including data harvested by embedded SDKs.
How it's found
Detected by reviewing the app's data collection and third-party SDK traffic for personal-data exposure beyond what the app discloses.
Standards mapping
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Exposure of Sensitive Information to an Unauthorized Actor using Nuclei's exposure templates (exposed configuration files, admin panels, API keys, .env and .git paths), with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 8 dedicated rules for this weakness.
Tools: Nuclei
Frequently asked questions
What is M6:2024 Inadequate Privacy Controls?
Collection, retention, or third-party sharing of personal data beyond what the app discloses to the user, including data harvested by embedded SDKs.
How do you find Inadequate Privacy Controls?
Detected by reviewing the app's data collection and third-party SDK traffic for personal-data exposure beyond what the app discloses.
Which CWEs map to M6:2024?
M6:2024 maps to CWE-200, CWE-359.
Does TurboPentest test for Inadequate Privacy Controls?
TurboPentest's automated black-box pentest actively probes for Exposure of Sensitive Information to an Unauthorized Actor using Nuclei's exposure templates (exposed configuration files, admin panels, API keys, .env and .git paths), with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 8 dedicated rules for this weakness.
Related OWASP categories
- OWASP Mobile Top 10M1:2024: Improper Credential Usage
- OWASP Mobile Top 10M2:2024: Inadequate Supply Chain Security
- OWASP Mobile Top 10M3:2024: Insecure Authentication/Authorization
- OWASP Mobile Top 10M4:2024: Insufficient Input/Output Validation
- OWASP Mobile Top 10M5:2024: Insecure Communication
- OWASP Mobile Top 10M7:2024: Insufficient Binary Protections
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest