Lookout launches MSEC to map mobile app vulnerabilities

Lookout launched Mobile Security Exposure Center to scan enterprise mobile fleets, build SBOMs from app binaries and map components to vulnerability lists like CISA’s KEV.

Lookout has launched the Mobile Security Exposure Center, a tool that scans enterprise mobile device fleets, builds software bills of materials (SBOMs) from app binaries and maps app components to public vulnerability databases such as CISA’s Known Exploited Vulnerabilities (KEV) catalog to flag exposures across devices, users and apps.

MSEC inspects each device to identify installed applications, then analyzes each app binary to produce an SBOM listing the libraries, components and dependencies inside the app. Those components are compared with public vulnerability repositories and internal threat data. The results can be integrated into an organization’s cyber threat and exposure management workflow to help security teams prioritize and remediate risky apps and components.

Lookout describes the system as able to show which apps use a particular vulnerable library, the app version and the specific user and device involved. The company says those details support targeted actions such as removing an app, pushing updates or isolating affected devices.

Jim Dolce, Lookout’s chief executive, pointed to a recent vulnerability in WolfSSL as an example of the type of exposure MSEC can help detect. WolfSSL is a small SSL/TLS library used in constrained devices and embedded in more than a billion devices. A public project flagged a flaw in the library that could let an attacker mimic a banking app and capture credentials. Dolce argued that knowing only an app’s name and version does not reveal whether it includes a specific vulnerable component.

Lookout positions MSEC as complementary to its AI Visibility & Governance product by adding a software composition and exposure view for mobile applications. The company said the combined data is intended to give security teams a wider view of application risk and governance across an enterprise.

MSEC’s current detections depend on matching discovered components against known vulnerability lists such as KEV. Lookout acknowledges those lists cover only publicly known flaws. The company plans a future update that will apply large AI models to SBOMs to search for previously unknown vulnerabilities and catalog new findings.

Lookout designed MSEC to feed its findings into remediation workflows so security teams can act on component-level exposures tied to the affected app, the user and the device. The product targets organizations where mobile devices operate outside traditional corporate perimeters and where teams need greater visibility into the internal makeup of mobile applications.

Articles by this author