Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[PT] Bit2me | Mobile | Jan2024

Date:

Mar 1, 2024

Table of Content

→Introduction
→Audit Summary
→Document Information
→System Overview
→Executive Summary
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Bit2Me team for the collaborative engagement that enabled the execution of this Security Assessment.

titlecontent
PlatformiOS, Android
Timeline3 Jan 2024 - 19 Jan 2024

    Protect your dApp with insights like these.

    Audit Summary

    Total10/10
    Security Score

    10/10

    Test Coverage

    \-

    Code Quality Score

    \-

    Documentation Quality Score

    \-

    10Total Findings
    7Resolved
    3Accepted
    0Mitigated

    The system users should acknowledge all the risks summed up in the risks section of the report

    Document Information

    This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.

    The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.

    Document

    NameMobile Application Penetration Test Report for Bit2me
    Audited ByEce Orsel
    Approved ByStephen Ajayi
    Websitehttps://bit2me.com→
    Changelog29/02/2024 - Final Report
    • Document

      Name
      Mobile Application Penetration Test Report for Bit2me
      Audited By
      Ece Orsel
      Approved By
      Stephen Ajayi
      Changelog
      29/02/2024 - Final Report

    System Overview

    The following table provides a synopsis of target systems that were within the scope of this Security Assessment.

    Bit2Me Mobile Application: iOS, Android

    Executive Summary

    Security score

    Upon auditing, the code was found to contain 0 critical, 0 high, 0 medium, and 6 low severity issues, leading to a security score of 10 out of 10.  After the completion of the remediation check, the status of the previously identified security vulnerabilities is as follows: 1 low severity vulnerabilities were accepted. 6 low severity and one informational severity vulnerability were successfully fixed.

    All identified issues are detailed in the “Findings” section of this report.

    Summary

    The overall rating of Customer Applications, after the security assessment by the Consultant’s Security Team, stands out to be 10 out of 10. The security assessment was carried out following the in-house test cases, manual methods, exploitation, and automated tools.

    Findings

    F-2024-0533Input fields with sensitive data should be cleared after hiding/opening the application
    Status
    fixed
    Severity

    Low
    F-2024-0528Application Vulnerable to Janus Vulnerability
    Status
    fixed
    Severity

    Low
    F-2024-0527Missing Security Headers
    Status
    fixed
    Severity

    Low
    F-2024-0526Application Running in Emulator
    Status
    fixed
    Severity

    Low
    F-2024-0525Lack of Obfuscation or Encryption in Code
    Status
    fixed
    Severity

    Low
    F-2024-0523Insecure Storage of Sensitive Data in NSUserDefaults
    Status
    accepted
    Severity

    Low
    F-2024-0532Use of Malloc Function Leading to Uncontrolled Memory Allocation
    Status
    fixed
    Severity

    Observation
    F-2024-0531Use of Insecure API(s) in Application Binary
    Status
    accepted
    Severity

    Observation
    F-2024-0529Unprotected Service Accessible to Other Applications
    Status
    accepted
    Severity

    Observation
    F-2024-0524Exposure of Unique Identifiers
    Status
    fixed
    Severity

    Observation
    Code
    ―
    Title
    Status
    Severity
    F-2024-0533Input fields with sensitive data should be cleared after hiding/opening the application
    fixed

    Low
    F-2024-0528Application Vulnerable to Janus Vulnerability
    fixed

    Low
    F-2024-0527Missing Security Headers
    fixed

    Low
    F-2024-0526Application Running in Emulator
    fixed

    Low
    F-2024-0525Lack of Obfuscation or Encryption in Code
    fixed

    Low
    F-2024-0523Insecure Storage of Sensitive Data in NSUserDefaults
    accepted

    Low
    F-2024-0532Use of Malloc Function Leading to Uncontrolled Memory Allocation
    fixed

    Observation
    F-2024-0531Use of Insecure API(s) in Application Binary
    accepted

    Observation
    F-2024-0529Unprotected Service Accessible to Other Applications
    accepted

    Observation
    F-2024-0524Exposure of Unique Identifiers
    fixed

    Observation
    1-10 of 10 findings

    Uncover findings like these to secure your project.

    Appendix 1. Severity Definitions

    Severity

    Description

    Critical
    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    High
    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Medium
    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Low
    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
    • Severity

      Critical

      Description

      These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

      Severity

      High

      Description

      These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

      Severity

      Medium

      Description

      These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

      Severity

      Low

      Description

      These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

    Appendix 2. Scope

    The scope of the project includes the following :

    Scope Details

    Mobile ApplicationAndroid and iOS→
    APINot Required
    WhitepaperNot Required
    RequirementsNot Required
    Technical RequirementsNot Required
    • Scope Details

      Mobile Application
      Android and iOS→
      API
      Not Required
      Whitepaper
      Not Required
      Requirements
      Not Required
      Technical Requirements
      Not Required

    Assets in Scope

    Android Mobile Application - Android Mobile Application
    iOS Mobile Application - iOS Mobile Application