MSAL - Xamarin Forms - iOS and Android - Penetration Test - Password is disclosed in the process where app is running

Baluprasath Sampath Kumar 1 Reputation point
2021-04-07T03:10:06.11+00:00

Hi,

We have implemented the MSAL authentication with EmbeddedWebView for Xamarin Forms Mobile app(iOS and Android).

The issue is when the app is penetration tested, they could find the password is being saved inside the app process and it can be easily retrieved.

MSAL library exposing sensitive information to the attackers.

Would be helpful if it is addressed earlier ASAP.

Regards,
Baluprasath S

Developer technologies | .NET | Xamarin
Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.