Zimperium

35 STATS6 REPORTS

All Statistics

Around 19% of Android shopping apps expose at least one unprotected exported Service, potentially leading to data leakage.

ZimperiumzLabs Mobile Shopping Report ·Nov 13, 2025
Android shopping app

Approximately 24% of analyzed Android shopping apps can retrieve Java classes or DEX files from remote locations.

ZimperiumzLabs Mobile Shopping Report ·Nov 13, 2025
Android shopping app

Roughly 29% of reviewed iOS shopping apps access user data without declaring it in their App Store Privacy Overview.

ZimperiumzLabs Mobile Shopping Report ·Nov 13, 2025
iOS shopping appData exposureApp StoreApp Store Privacy Overview

During the 2024 shopping season, there was a 4x increase in mishing sites compared to monthly averages.

ZimperiumzLabs Mobile Shopping Report ·Nov 13, 2025
Mishing

3 VPN apps still utilized a legacy version of the OpenSSL library.

ZimperiumInsecure Mobile VPNs: The Hidden Danger ·Oct 2, 2025
VPN

25% of the VPN apps analyzed on iOS failed to include a valid privacy manifest at all.

ZimperiumInsecure Mobile VPNs: The Hidden Danger ·Oct 2, 2025
VPN

On iOS, over 6% of VPN apps were found requesting private entitlements, which are typically restricted from third-party developers. This represented a total of 30 apps

ZimperiumInsecure Mobile VPNs: The Hidden Danger ·Oct 2, 2025
VPN

Approximately 1% of the analyzed VPN apps were found to be vulnerable to a Man-in-the-Middle (MitM) attack.

ZimperiumInsecure Mobile VPNs: The Hidden Danger ·Oct 2, 2025
VPN

50% of mobile devices are running on outdated operating systems.

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
MobileOS

Nearly 60% of iOS apps are vulnerable to PII data leakage.

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
MobileiOSPIIData leakage

Over 60% of iOS apps lack basic code protection.

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
MobileiOS

Up to 34% of Android apps lack basic code protection.

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
MobileAndroid

Over 25% of mobile devices cannot upgrade to the latest OS versions.

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
MobileOS

43% of Android apps are vulnerable to PII data leakage.

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
MobileAndroidPIIData leakage

Smishing has rapidly grown to comprise over two-thirds of mobile phishing attacks. Specifically, SMS/text based phishing (Smishing) is now 69.3% of all mishing attacks.

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
MobilePhishingSmishing

Smishing attacks grew by 22%.

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
MobilePhishingSmishing

70% of organizations support BYOD (Bring Your Own Device)

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
BYOD

50% of mobile devices are running on outdated operating systems.

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
MobileOS

There was a 50% increase year-over-year in the use of Trojans in attacks.

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
MobileTrojan

Vishing (voice-call phishing) tactics grew by 28%.

Zimperium2025 Global Mobile Threat Report·Apr 28, 2025
MobilePhishingVishing

43% of the top 100 apps use one or more cryptographic methods that do not follow best practices.

ZimperiumYour Apps are Leaking: The Hidden Data Risks on your Phone·Apr 16, 2025
AppCryptographic

88% of all apps use one or more cryptographic methods that do not follow best practices.

ZimperiumYour Apps are Leaking: The Hidden Data Risks on your Phone·Apr 16, 2025
AppCryptographic

103 of 9,078 analyzed Android apps were found to use unprotected or misconfigured cloud storage. 4 of these Android apps were in the top 1000 of the PlayStore popularity list.

ZimperiumYour Apps are Leaking: The Hidden Data Risks on your Phone·Apr 16, 2025
AppAndroidCloud

62% of all analysed apps use some kind of cloud API or SDK.

ZimperiumYour Apps are Leaking: The Hidden Data Risks on your Phone·Apr 16, 2025
App

10 of analyzed 9,078 Android apps contained exposed credentials to AWS cloud services.

ZimperiumYour Apps are Leaking: The Hidden Data Risks on your Phone·Apr 16, 2025
AppAndroidExposed credentialsAWS cloud service

Rooted devices are more than 3.5 times more likely to be targeted by mobile malware.

ZimperiumCatch Me If You Can: Rooting Tools vs The Mobile Security Industry·Mar 14, 2025
RootingMalwareMobile SecurityEnterprise Security

System compromise incidents are 250 times higher on rooted devices compared to stock devices.

ZimperiumCatch Me If You Can: Rooting Tools vs The Mobile Security Industry·Mar 14, 2025
RootingSystem CompromiseThreat StatisticsStock Devices

Events where Security-Enhanced Linux is disabled increase more than 90 times on rooted devices compared to stock devices.

ZimperiumCatch Me If You Can: Rooting Tools vs The Mobile Security Industry·Mar 14, 2025
RootingSecurity-Enhanced LinuxThreat StatisticsStock Devices

Filesystem compromise events increase by a factor of 3000 on rooted devices compared to stock devices.

ZimperiumCatch Me If You Can: Rooting Tools vs The Mobile Security Industry·Mar 14, 2025
RootingFilesystem CompromiseThreat StatisticsStock Devices

The exposure factor of rooted devices versus stock devices varies from 3x to ~3000x, which suggests that rooted devices are potentially much more vulnerable to threats than stock devices.

ZimperiumCatch Me If You Can: Rooting Tools vs The Mobile Security Industry·Mar 14, 2025
RootingSecurity RiskMobile SecurityThreat Exposure

Compromised app detections surge by a factor of 12 on rooted devices compared to stock devices.

ZimperiumCatch Me If You Can: Rooting Tools vs The Mobile Security Industry·Mar 14, 2025
RootingApp SecurityThreat StatisticsStock Devices

3% of phishing sites use device-specific redirection, showing benign content on desktops while targeting mobile devices with phishing payloads.

ZimperiumzLabs Mishing Report: The Evolution of Mobile-Specific Phishing Attacks·Feb 1, 2025

Quishing (QR code phishing) is emerging, with notable activity in Japan (17%), the U.S. (15%), and India (11%).

ZimperiumzLabs Mishing Report: The Evolution of Mobile-Specific Phishing Attacks·Feb 1, 2025

Smishing (SMS/text based phishing) is the most common mobile phishing vector, accounting for 37% of attacks in India, 16% in the U.S., and 9% in Brazil.

ZimperiumzLabs Mishing Report: The Evolution of Mobile-Specific Phishing Attacks·Feb 1, 2025

Mishing activity peaked in August 2024, with over 1,000 daily attack records.

ZimperiumzLabs Mishing Report: The Evolution of Mobile-Specific Phishing Attacks·Feb 1, 2025