🇳🇴 Join our 1st Vibe Coding Security Wokrshop & Wargame at NDC Oslo

OWASP Mobile Top 10 · 2024 edition

OWASP Mobile Top 10 Challenges

Cover the OWASP Mobile Top 10 (2024) with hands-on Android and iOS challenges. Developers fix real vulnerabilities in real mobile apps and build the habits that keep your releases off the incident report.

Ready when the auditor asks

Generate Your OWASP Mobile Top 10 Training Report

Every completed challenge rolls up into a OWASP Mobile Top 10 training report. Point and click to generate it, then hand it straight to your auditor, customer or partner the moment they ask for evidence.

Capability, not checkbox compliance

Hands-On Challenges for Every Category

The OWASP Mobile Top 10 (2024) is the benchmark for mobile application security. Every challenge below is a real Android or iOS app with a real vulnerability: developers fix it without breaking functionality, and every verified fix becomes reportable evidence of mobile security capability.

M4:2024

Insufficient Input/Output Validation

Untrusted data from intents, deep links and IPC processed without validation.

M7:2024

Insufficient Binary Protections

Apps shipped without obfuscation or integrity protections, making reverse engineering trivial.

Roll it out

Turn the Standard Into a Training Program

Assign these challenges to your team as learning pathways, track verified fixes, and report OWASP Mobile Top 10 coverage to auditors, customers and the board, with evidence, not attendance sheets.