Lookout Inc. has introduced the Mobile Software Exposure Center, a new capability within its Mobile Endpoint Security platform designed to scan and assess hidden vulnerabilities in mobile apps running on employee devices.
- Inspects mobile apps at binary level without source code access
- Flags vulnerable or outdated third-party components in apps
- Integrates with endpoint management to block high-risk apps
What happened
Lookout Inc. launched the Mobile Software Exposure Center, a tool embedded within its Lookout Mobile Endpoint Security platform to continuously identify, assess, and prioritize software exposure risks found in mobile applications deployed on corporate devices. The solution works by fingerprinting the compiled code of Android and iOS apps and generating a software bill of materials for each application.
It then cross-references each component against known vulnerability databases and threat intelligence feeds to identify security gaps such as outdated libraries, embedded vulnerable SDKs, and third-party APIs that can be exploited. The product aims to close a critical security gap not covered by traditional mobile device management solutions, which often cannot inspect the software supply chain inside mobile apps.
Why it matters
Enterprise security tools have generally been optimized for desktops and cloud workloads, overlooking the complexities of mobile apps that combine open-source libraries, SDKs, and APIs from multiple vendors. This fragmented software supply chain creates hidden risks that attackers, especially those leveraging new AI-driven techniques, can exploit rapidly with little human intervention.
Lookout’s entry into this space addresses a pressing need as automated discovery of mobile app vulnerabilities has become faster due to advancements in frontier AI models. The company demonstrated this threat landscape with its recent detection of the DarkSword iOS exploitation framework. As mobile apps increasingly become attack vectors, continuous, automated visibility into software exposure is essential for preventing breaches.
What to watch next
Lookout plans to expand the integration of the Mobile Software Exposure Center within existing device and endpoint management infrastructures to allow seamless enforcement of mitigation policies, such as automatically restricting or removing high-risk applications. Enterprise adoption of this tool will likely depend on how effectively it can reduce risk without disrupting user productivity.
Future developments may also respond to evolving AI-driven threat techniques by further automating the prioritization and remediation workflows. Given Lookout’s extensive telemetry from over 235 million devices and 400 million applications, continuous updates to vulnerability intelligence will be critical in maintaining effective defense against emerging mobile software threats.