Mobile Attack Surface Risk Simulator
Interactive OWASP Mobile Top-10 attack-surface simulator: toggle mitigations across insecure storage, weak crypto, insecure comms, reverse engineering and more to see each vulnerability's exploit-likelihood and impact combine into a live total risk score.
Real mobile apps are not vulnerable in one place — the OWASP Mobile Top-10 lists a whole portfolio of independent weaknesses: how data is stored on the device, how it is encrypted, how it travels over the network, how easy the binary is to reverse-engineer, how login and session state are protected, how untrusted input is validated, how the release build is configured, and how much risk third-party SDKs bring in. This simulator scores each of those surfaces separately from its own base exploit-likelihood and impact, then lets you flip each surface's specific mitigation on or off to see it — and only it — shrink. Attack particles stream continuously from every surface toward the app core; watch which ones get through and which get deflected as you build out a realistic defense-in-depth posture, and see how a stronger attacker changes the calculus everywhere at once.
Assess risk across OWASP Mobile Top-10 attack surfaces by adjusting base likelihood and impact of each surface, then applying mitigations to reduce risks.
2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install