Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • Application SecurityAI

Novee Expands AI Penetration Testing Platform to Mobile Applications


Novee Expands AI Penetration Testing Platform to Mobile Applications
  • by: GlobeNewswire
  • |
  • July 31, 2026

Novee has expanded its AI-powered penetration testing platform to include mobile applications, extending continuous security testing across the modern application attack surface. The new capability enables organizations to perform autonomous mobile application security testing alongside web applications, APIs, desktop software, and AI-enabled applications, helping security teams identify vulnerabilities before attackers exploit them.

Quick Intel

  • Novee expands its AI penetration testing platform to support mobile applications.
  • The platform now provides continuous testing across web, APIs, desktop, AI, LLM, and mobile apps.
  • Mobile assessments combine static analysis with live runtime testing.
  • Security findings align with OWASP MASVS and MASTG standards.
  • Novee research uncovered multiple Android security vulnerabilities, including account takeover risks.
  • The new mobile testing capability is available immediately through the existing platform.

Novee Brings Continuous AI Penetration Testing to Mobile Apps

Novee has introduced continuous AI-powered penetration testing for mobile applications, expanding its offensive security platform beyond web applications, APIs, desktop software, and AI-powered applications.

The platform is designed to transform traditional mobile penetration testing from periodic security assessments into an ongoing process. Organizations can upload a mobile application package and receive detailed security findings within hours alongside results from other application assets.

AI Platform Simulates Real-World Mobile Attacks

The mobile security capability combines static code analysis with live runtime testing to evaluate how applications behave in real-world environments.

Novee reverse-engineers application packages to identify hidden entry points before executing them in a fully instrumented environment. The platform analyzes application behavior, network communications, and locally stored data, helping security teams uncover backend connections and vulnerabilities that conventional security scans may overlook.

Security Testing Aligns with OWASP Standards

Every mobile security assessment maps directly to the OWASP Mobile Application Security Verification Standard (MASVS) and the Mobile Application Security Testing Guide (MASTG).

Each finding includes exploit evidence, replication steps, and remediation guidance tailored to the application's technology stack. After vulnerabilities are fixed, the platform automatically retests the application to verify that the security risks have been successfully resolved.

Mobile Security Research Identifies Critical Android Vulnerabilities

To support the platform's launch, Novee shared findings from its mobile security research.

After manually discovering seven Universal Cross-Site Scripting (UXSS) vulnerabilities in Android WebView, researchers expanded testing across 20 Android applications. The AI platform identified additional UXSS vulnerabilities along with a critical account takeover vulnerability.

The research highlighted security weaknesses that occur when native application code communicates with web content without validating whether the original webpage remains active. As a result, Novee now continuously tests Android applications for origin validation flaws, navigation weaknesses, and bridge authentication issues.

Leadership Highlights Need for Connected Application Security

“Attackers do not respect the boundaries organizations draw between their application assets. They look for the weakest entry point, then move across the connected environment to reach sensitive data,” said Omer Ninburg, Co-founder and Chief Technical Officer at Novee.

“A mobile app can expose functionality and backend APIs that are not visible through the web front end. Novee research into twenty Android Apps has already uncovered over a dozen repetitions of such a chained exploit in a customer’s environment. Security teams need to test those connections as a real attacker would, not evaluate the mobile client as an isolated piece of software.”

By extending its AI penetration testing platform to mobile applications, Novee enables organizations to secure increasingly connected application environments through continuous, autonomous security testing. The expanded platform strengthens enterprise cybersecurity by helping security teams identify vulnerabilities across web, mobile, APIs, desktop, and AI applications before they can be exploited.

About Novee

Novee is the AI penetration testing platform built to secure constantly changing environments against attackers operating at machine speed. Its purpose-trained AI reasons like a real attacker, uncovers novel attack paths continuously, and delivers precise, personalized fixes so teams can stay one step ahead of hackers. Founded by national-level offensive security leaders Ido Geffen, Gon Chalamish, and Omer Ninburg, Novee has raised $51.5 million within four months of its inception from leading investors including YL Ventures, Canaan Partners, and Zeev Ventures. Learn more at novee.security.

  • CybersecurityPenetration TestingMobile SecurityApplication SecurityAI Security
News Disclaimer
  • Share