Novee Expands AI Pentesting Platform to Mobile Applications
Novee has launched its AI-powered penetration testing platform for mobile applications, aiming to provide continuous, autonomous security testing across a wider range of digital assets.
Novee has announced a significant expansion of its AI penetration testing platform, now encompassing mobile applications. This move positions Novee as a comprehensive AI pentesting solution, capable of providing continuous and autonomous security coverage across the modern application attack surface, including web applications, APIs, desktop applications, and AI/LLM-enabled software.
The platform aims to fundamentally shift mobile penetration testing from a periodic, often infrequent, assessment to an ongoing security practice. Users can now upload their mobile application packages and receive detailed security findings within hours, integrated with results from their other application assets. This continuous approach allows organizations to proactively identify and address vulnerabilities as they emerge.
Omer Ninburg, Co-founder and CTO at Novee, highlighted the interconnected nature of modern application environments. "Attackers do not respect the boundaries organizations draw between their application assets. They look for the weakest entry point, then move across the connected environment to reach sensitive data," Ninburg stated. He further explained that mobile applications can expose functionality and backend APIs that might be hidden from web front-end assessments. Novee's research has already uncovered instances of chained exploits originating from mobile apps in customer environments, underscoring the need to test these connections comprehensively.
Novee's methodology combines static analysis with live runtime testing to gain a deep understanding of an application's actual behavior. The platform reverse-engineers application packages to uncover entry points that traditional scanning tools might miss. It then executes the application in a fully instrumented environment to meticulously analyze its behavior, network traffic, and locally stored data. This detailed analysis is crucial for exposing hidden functionality and backend connections that could be masked by encrypted or pinned traffic.
Each assessment conducted by Novee is mapped to industry standards, including the OWASP Mobile Application Security Verification Standard (MASVS) and the Mobile Application Security Testing Guide (MASTG). The findings provided to users include concrete exploit evidence, detailed replication steps, and tailored remediation advice specific to the application's technology stack. A key feature of the platform is its automated retesting capability, which confirms that a vulnerability has been successfully closed after a fix is implemented.
Supporting this expansion, Novee has also shared new research demonstrating the effectiveness of its continuous AI pentesting for mobile. Following the manual discovery of seven Universal Cross-Site Scripting (UXSS) vulnerabilities in Android WebView, Novee researchers formalized the attack patterns and directed their platform to test 20 additional Android applications. This proactive testing uncovered further UXSS vulnerabilities, alongside a critical account takeover vulnerability. The research identified security gaps arising from native code sending information back to web content without proper origin validation, issues Novee now actively tests for in its mobile assessments.
Continuous AI pentesting for mobile is available immediately as part of Novee's existing platform offerings. The company will also be presenting at Black Hat USA 2026, with researchers leading briefing sessions and available at booth #5323 to discuss their offensive security solutions. Interested parties can also schedule a demo or a more in-depth discussion with Novee's co-founders.