Skip to content

This release includes breaking changes for platform teams planning a safe upgrade.

โœ“ No known CVEs patched
Read the diff โ†’ Tool health โ†’ What is this tool? โ†’

✓ No known CVEs patched in this version

Topics

android android-application compliancy-checklist dynamic-analysis hacking ios
+13 more
ios-app mast mastg mobile-app mobile-security mstg network-analysis pentesting reverse-engineering reverse-enginnering runtime-analysis static-analysis testing-cryptography

Affected surfaces

auth rbac crypto_tls deps

Summary

AI summary

Broad release touches v1 โ†’ v2 Ports, โœจ MASTG Techniques, New Weaknesses, and ๐ŸŽฌ MASTG Demos.

Full changelog

v1.9.0 Release Notes

This release spans January โ€“ December 2025 and is the largest in the project's history by volume: over 2,000 commits, dozens of v1โ†’v2 test ports, a complete CWE mapping across all MASVS categories, new knowledge and best practice content, and several major structural milestones โ€” including MASTG v2 graduating from beta, the MAS website moving to its own repository, and Guardsquare joining NowSecure as an OWASP MAS Advocate.

The year opened with the three-year anniversary of NowSecure as an OWASP MAS Advocate, reflecting on more than 320 pull requests, 230 reviews, and 42,000+ additions to the MASTG โ€” a partnership that has been instrumental in driving the v2 refactor forward. Alongside this, the MAS Task Force (launched in February 2024) continued to meet monthly, coordinating the porting effort and shaping the project roadmap.

In May 2025, Guardsquare officially achieved MAS Advocate status โ€” the highest recognition in the project. Their sustained contributions, including the bulk of the v1โ†’v2 test ports in this release, and their key role in the OWASP Project Summit 2024, made them a natural fit. This release contains the most visible result of that commitment: a major wave of tests fully ported to the v2 format by Dennis Titze, Jan Seredynski, Nuno Antunes, and Pascal Jungblut.

The defining technical milestone of the year was the removal of the beta label from MASTG v2 and the deprecation of the legacy PDF format โ€” a signal that the new modular structure is now the primary and stable reference. Alongside this, two major extractions reshaped the project structure: MASWE was temporarily moved to its own OWASP/maswe repository (and later re-integrated), and the MAS website was extracted to OWASP/mas-website, allowing each to evolve independently.


๐Ÿ“ข News

  • NowSecure: 3 years as OWASP MAS Advocate โ€” #3253
  • Guardsquare achieves MAS Advocate status by @cpholguera โ€” #3285
  • Safe App Standard v2.0 adoption update by @userdehghani โ€” #3254
  • New talk: OWASP AppSec US 2024 (San Francisco) by @sushi2k โ€” #3143
  • New talk: OWASP AppSec EU 2025 by @sushi2k โ€” #3345

๐Ÿ›๏ธ Major Structural Milestones

  • MASTG v2 exits beta โ€” removed beta status, deprecated legacy PDF format by @cpholguera โ€” #3295
  • MASWE temporarily extracted to OWASP/maswe as a dedicated repo, then re-integrated into MASTG by @cpholguera โ€” #3395, #3398, #3400
  • MAS Website extracted to OWASP/mas-website by @cpholguera โ€” #3426, #3459
  • MAS-P Privacy profile added, covering all MASVS-PRIVACY test cases by @Diolor โ€” #3496
  • MAS Testing Profiles applied to all v2 test cases and documented by @cpholguera โ€” #3315, #3483

๐Ÿ› MASWE โ€” MAS Weaknesses

New Weaknesses

  • [MASWE-0020] Weak Encryption (by @appknox) by @sk3l10x1ng โ€” #2910
  • [MASWE-0023] Weak Padding by @jmariasantosdekra โ€” #2922
  • [MASWE-0047โ€“0052] New weaknesses by @cpholguera โ€” #2919
  • [MASWE-0067] Debuggable Flag Not Disabled (by @appknox) by @ScreaMy7 โ€” #3244
  • [MASWE-0076] Dependencies with Known Vulnerabilities (SBOM) by @sushi2k โ€” #2912
  • [MASWE-0117] Inadequate Permission Management (by @NowSecure) by @cpholguera โ€” #3119

CWE Mapping

Complete CWE mapping added across all MASVS categories by @truerick and @poffo-mobisec:

  • MASVS-AUTH-1 โ€” #3133 ยท AUTH-2 โ€” #3137 ยท AUTH-3 โ€” #3138
  • MASVS-CRYPTO-1 โ€” #3139 ยท CRYPTO-2 โ€” #3140
  • MASVS-NETWORK-1 โ€” #3141 ยท NETWORK-2 โ€” #3142
  • MASVS-PLATFORM-3 โ€” #3144 ยท PLATFORM (full) โ€” #3149
  • MASVS-STORAGE-1 โ€” #3145 ยท STORAGE-2 โ€” #3146
  • MASVS-CODE โ€” #3152
  • MASVS-RESILIENCE โ€” #3151

๐Ÿงช MASTG Tests

v1 โ†’ v2 Ports (by @guardsquare)

  • MASTG-TEST-0006 by @serek8 โ€” #3055
  • MASTG-TEST-0009 by @serek8 โ€” #3028
  • MASTG-TEST-0010, MASTG-TEST-0059 by @serek8 โ€” #3112
  • MASTG-TEST-0012 by @serek8 โ€” #3113
  • MASTG-TEST-0015 by @serek8 โ€” #3525
  • MASTG-TEST-0022 by @titze โ€” #3035
  • MASTG-TEST-0041 by @titze โ€” #3242
  • MASTG-TEST-0052 by @serek8 โ€” #3045
  • MASTG-TEST-0053 by @serek8 โ€” #3038
  • MASTG-TEST-0054 by @serek8 โ€” #3047
  • MASTG-TEST-0055 by @serek8 โ€” #3054
  • MASTG-TEST-0058 by @serek8 โ€” #3039
  • MASTG-TEST-0073 by @pascalj โ€” #3051

v1 โ†’ v2 Ports (by @appknox)

  • MASTG-TEST-0024 by @ScreaMy7 โ€” #3076
  • MASTG-TEST-0082 by @jeel38 โ€” #3097
  • MASTG-TEST-0088 by @sk3l10x1ng โ€” #3073

v1 โ†’ v2 Ports (community)

  • MASTG-TEST-0004 by @Diolor โ€” #3485
  • MASTG-TEST-0005 by @Diolor โ€” #3464
  • MASTG-TEST-0008 by @Diolor โ€” #3495
  • MASTG-TEST-0014 (by @NowSecure) by @cpholguera โ€” #3551
  • MASTG-TEST-0021 by @sydseter โ€” #3255
  • MASTG-TEST-0023 (by @NowSecure) by @cpholguera โ€” #3423
  • MASTG-TEST-0032 (by @NowSecure) by @cpholguera โ€” #3177
  • MASTG-TEST-0040 (by @NowSecure) by @cpholguera โ€” #3417
  • MASTG-TEST-0042, MASTG-TEST-0085, MASWE-0076 โ€” Dependencies with Known Vulnerabilities (SBOM) by @sushi2k โ€” #2912
  • MASTG-TEST-0061, MASTG-TEST-0062 by @sydseter โ€” #3194
  • MASTG-TEST-0063 (by @NowSecure) by @cpholguera โ€” #3521
  • MASTG-TEST-0064 by @serek8 โ€” #3256

New v2 Tests

  • MASTG-TEST-0262, MASTG-TEST-0263: Android backup testing by @cpholguera โ€” #3217
  • MASTG-TEST-0264, MASTG-TEST-0265: StrictMode detection by @cpholguera โ€” #3246
  • MASTG-TEST-0278, MASTG-TEST-0279, MASTG-TEST-0280: iOS UIPasteboard by @cpholguera โ€” #3289
  • iOS ECB insecure encryption modes test and demo by @Diolor โ€” #3547
  • New Android privacy test case drafts by @cpholguera โ€” #3228

Updates & Fixes

  • MASTG-TEST-0210: add Blowfish and third-party / custom implementations by @cpholguera โ€” #3369
  • MASTG-TEST-0228: remove unnecessary step by @barbieri-mobisec โ€” #3106
  • MASTG-TEST-0281: improved steps and criteria, add MASTG-TECH-0136, 0137, 0138 by @cpholguera โ€” #3338
  • MASTG-TEST-0016: marked as covered by v2 (by @guardsquare) by @nmsa โ€” #3026
  • Keyboard caching theory for Android enhanced (by @NowSecure) by @cpholguera โ€” #3237
  • Cryptographic language standardized (e.g. "weak") by @sydseter โ€” #3199

Deprecations

  • MASTG-TEST-0031: Testing JavaScript Execution in WebViews โ€” deprecated by @cpholguera โ€” #3419
  • Memory corruption and sensitive data tests deprecated for Android and iOS by @cpholguera โ€” #3506
  • EncryptedFile / EncryptedSharedPreferences deprecation warnings added by @AndrewScull โ€” #3158

๐ŸŽฌ MASTG Demos

  • MASTG-DEMO-0034, MASTG-DEMO-0035: Android backup via adb and semgrep (by @NowSecure) by @cpholguera โ€” #3217
  • MASTG-DEMO-0038, MASTG-DEMO-0039: StrictMode detection (by @NowSecure) by @cpholguera โ€” #3246
  • MASTG-DEMO-0048, MASTG-DEMO-0049 (by @NowSecure) by @cpholguera โ€” #3274
  • MASTG-DEMO-0060: EncryptedSharedPreferences secure storage (by @NowSecure) by @cpholguera โ€” #3410
  • MASTG-DEMO-0040: Debuggable Flag Not Disabled (by @appknox) by @ScreaMy7 โ€” #3244
  • Demo download buttons: direct APK/IPA download by @TheDauntless โ€” #3348
  • Add demo status display and draft banner by @cpholguera โ€” #3208
  • Fix all demos for Frida 17 breaking changes by @cpholguera โ€” #3364
  • Update MASTG-DEMO-0009: focus on undeclared PII in network traffic by @cpholguera โ€” #3502
  • Update MASTG-DEMO-0027: Frida script flags and result lookup by @cpholguera โ€” #3363
  • Update MASTG-DEMO-0058, MASTG-DEMO-0059 by @cpholguera โ€” #3460

๐Ÿ›ก๏ธ MASTG Best Practices

  • MASTG-BEST-0004: link to security recommendations for backups by @cpholguera โ€” #3118
  • Enhanced error and exception handling best practices for Android by @cpholguera โ€” #3471

๐Ÿ“– MASTG Knowledge

  • Split Android and iOS platform security knowledge into distinct sections by @cpholguera โ€” #3413
  • MASTG-KNOW-0017: updated by @KVVat โ€” #3488

โœจ MASTG Techniques

  • [MASTG-TECH-0112] Reverse Engineering Flutter Applications by @Datafarm-Research โ€” #2913
  • [MASTG-TECH-0136, 0137, 0138] MITM techniques clarified and added (by @NowSecure) by @cpholguera โ€” #3184
  • New technique: Inspecting the Merged Android Manifest by @Diolor โ€” #3490
  • MASTG-TECH-0052: simulator commands updated by @cpholguera โ€” #3186
  • MASTG-TECH-0117: updated with jadx by @cpholguera โ€” #3334
  • MASTG-TECH-0058, MASTG-TECH-0111: properly linked to TOOL pages by @cpholguera โ€” #3342
  • IPA Installation Techniques updated (by @NVISOSecurity) by @TheDauntless โ€” #3100
  • Terminology: updated MITM to "Machine-in-the-Middle" by @sushi2k โ€” #3175

๐Ÿช„ MASTG Tools

New tools:

  • [MASTG-TOOL-0129] rabin2 by @cpholguera โ€” #3154
  • [MASTG-TOOL-0131] PlistBuddy and plistlib by @TheDauntless โ€” #3349
  • [MASTG-TOOL-0137] GlobalWebInspect, [MASTG-TOOL-0138] ipainstaller, [MASTG-TOOL-0139] ElleKit, [MASTG-TOOL-0140] frida-multiple-unpinning, [MASTG-TOOL-0141] IOSSecuritySuite, [MASTG-TOOL-0142] Choicy by @TheDauntless โ€” #3354
  • [MASTG-TOOL-0143] badssl.com (network testing) by @cpholguera โ€” #3372
  • [MASTG-TOOL-0144] gitleaks by @cpholguera โ€” #3467

New apps:

  • BugBazaar and iBugBazaar (vulnerable Android/iOS apps) by @krutarthshukla โ€” #3192
  • [MASTG-APP-0031] VulnForum (intentionally vulnerable Android app) by @macik09 โ€” #3514

Updates:

  • MASTG-TOOL-0031 (Frida): updated for Frida 17 breaking changes by @cpholguera โ€” #3362
  • MASTG-TOOL-0043 (class-dump): dockerized version added by @lucacapacci โ€” #3466
  • MASTG-TOOL-0064 (Sileo): updated (by @NVISOSecurity) by @TheDauntless โ€” #3104
  • MASTG-TOOL-0074 (objection): Frida 17+ support and new commands by @IPMegladon โ€” #3378
  • ProxyDroid updated (by @NVISOSecurity) by @TheDauntless โ€” #3111
  • MASTG-TECH-0017, MASTG-TECH-0023, MASTG-TOOL-0018 updated by @TheDauntless โ€” #3346
  • Add GitHub statistics to all GitHub-based tool pages by @TheDauntless โ€” #3350

Deprecations:

  • MASTG-TOOL-0023 (RootCloak), MASTG-TOOL-0046 (Cycript), MASTG-TOOL-0047 (Cydia) deprecated by @TheDauntless โ€” #3354

โšก Automation

  • iOS demo build pipeline via GitHub Actions (by @NowSecure) by @cpholguera โ€” #3125
  • Android demo build: simplified scripts, caching by @javier-ruiz-b โ€” #3157
  • Android demo build: proto files and build.gradle.kts support (by @NowSecure) by @cpholguera with @Copilot โ€” #3543
  • iOS build: Local.xcconfig copy step by @Diolor โ€” #3599
  • Only run APK/IPA builds on demo changes (PR-scoped) by @cpholguera โ€” #3205
  • Custom linting rules by @cpholguera โ€” #2816
  • Workflow to check for duplicate file IDs in PRs by @cpholguera โ€” #3202
  • Reusable GitHub Actions workflow for website build and deploy by @cpholguera โ€” #3325, #3326
  • pip install speed improved via action-setup-venv by @javier-ruiz-b โ€” #3336
  • Hooks refactored, tags upgraded, requirements fixed by @TheDauntless โ€” #3317

๐Ÿ—๏ธ Site & Infrastructure

  • Interactive test filters added to the tests index by @cpholguera โ€” #3332
  • Table search refactored by @TheDauntless โ€” #3340
  • Taxonomy section updated by @TheDauntless โ€” #3352
  • MAS Components authoring instructions added by @cpholguera โ€” #3447
  • Frida 17 base script PoC by @bernhste โ€” #3359
  • Data storage chapter updated: internal/external/scoped storage, APIs and permissions by @cpholguera โ€” #3179
  • Frida hook improvements: instance tracking, simpleHash, optional overload definitions (by @NowSecure) by @cpholguera โ€” #3553, #3556
  • ZAP references updated by @kingthorin โ€” #3169

๐Ÿž Errata Corrections

  • MSTG โ†’ MASTG rename sweep by @Diolor โ€” #3577
  • Grammar and punctuation fixes across Android techniques (TECH 1โ€“140) by @Diolor โ€” #3474, #3475, #3476, #3477, #3478
  • Fix link typo in security testing document by @mrjonstrong โ€” #3443
  • Fix various grammar mistakes in tools/android by @Diolor โ€” #3481
  • Update Salesforce link for ZAP setup by @Diolor โ€” #3480
  • Objection: remove outdated pip/PyPI warnings by @cpholguera with @Copilot โ€” #3550
  • Frida for iOS reference corrected to Frida for Android by @Stormtrooperroman โ€” #3501

๐ŸŽ‰ New Donators

  • Eydle joins as donator by @sushi2k โ€” #3122

New Contributors

  • @Datafarm-Research โ€” #2913
  • @barbieri-mobisec โ€” #3106
  • @poffo-mobisec โ€” #3133
  • @javier-ruiz-b โ€” #3157
  • @kingthorin โ€” #3169
  • @sydseter โ€” #3193
  • @userdehghani โ€” #3254
  • @Azulath โ€” #3260
  • @GSFZamai โ€” #3258
  • @emmanuel-ferdman โ€” #3272
  • @AndrewScull โ€” #3158
  • @nobodynate โ€” #3414
  • @mrjonstrong โ€” #3443
  • @bernhste โ€” #3359
  • @krutarthshukla โ€” #3192
  • @lucacapacci โ€” #3466
  • @Stormtrooperroman โ€” #3501
  • @IPMegladon โ€” #3378
  • @macik09 โ€” #3514
  • @Diolor โ€” #3474
  • @KVVat โ€” #3488

Full Changelog: https://github.com/OWASP/mastg/compare/v1.8.0...v1.9.0

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track OWASP Mobile Security Testing Guide

Get notified when new releases ship.

Sign up free

About OWASP Mobile Security Testing Guide

A comprehensive manual for mobile app security testing and reverse engineering.

All releases โ†’

Related context

Beta — feedback welcome: [email protected]