Low risk Medium risk High risk Blocked / deflected

Mobile Attack Surface Risk Simulator

Real mobile apps are not vulnerable in one place — the OWASP Mobile Top-10 lists a whole portfolio of independent weaknesses: how data is stored on the device, how it is encrypted, how it travels over the network, how easy the binary is to reverse-engineer, how login and session state are protected, how untrusted input is validated, how the release build is configured, and how much risk third-party SDKs bring in. This simulator scores each of those surfaces separately from its own base exploit-likelihood and impact, then lets you flip each surface's specific mitigation on or off to see it — and only it — shrink. Attack particles stream continuously from every surface toward the app core; watch which ones get through and which get deflected as you build out a realistic defense-in-depth posture, and see how a stronger attacker changes the calculus everywhere at once.