Mobile Application Security Testing (MAST) is the practice of finding and fixing security weaknesses in mobile apps before someone else finds them. It covers the code shipped inside the app, the data stored on the phone and the traffic between the app and your servers.
MAST combines static, dynamic and runtime analysis, secret detection and a software bill of materials. The reason it is its own field is that a mobile app runs on a device you do not control, where anyone can download it and take it apart.
See the full guide: What is mobile application security?
Related terms
Static Application Security Testing (SAST)Dynamic Application Security Testing (DAST)Interactive Application Security Testing (IAST)Software Bill of Materials (SBOM)Mobexa tests the exact Android or iOS build you ship and maps every finding to the OWASP Mobile Top 10 and MASVS.
Start Free Trial