An Empirical Security Assessment of Android-Based Social Media Applications in Thailand: A Multi-Method Approach Aligned with OWASP Mobile Top 10 (2024)

Chatphat Titiakarawongse, Benjamas Rueangphimai, Chanikan Weangnon

Abstract


Mobile social media applications are integral to communication and content sharing but remain highly susceptible to security and privacy threats. Whilst prior research has investigated mobile vulnerabilities, few studies have systematically analysed Android-based social media applications within regional contexts such as Thailand, where usage is extensive. This study addresses this gap through a multi-tool security assessment of eight widely used Android applications. Using MobSF, the AndroBugs Framework, and reverse engineering tools (APKTool, Dex2jar, JD-GUI), vulnerabilities were identified and categorised according to the OWASP Mobile Top 10 (2024) security categories. Results revealed that M9 (Insecure Data Storage) was present in all applications, whereas M6 (Inadequate Privacy Controls) was least frequent, and no occurrences of M1 (Improper Credential Usage) or M2 (Inadequate Supply Chain Security) were observed. X (formerly Twitter) exhibited the highest vulnerability count, whilst TikTok showed the fewest. The findings highlight the value of a multi-tool approach for comprehensive vulnerability detection and underscore the urgent need for improved data handling, cryptographic safeguards, and continuous security testing in mobile application development.


Full Text:

PDF


DOI: https://doi.org/10.11114/smc.v14i4.8850

Refbacks

  • There are currently no refbacks.


Studies in Media and Communication      ISSN 2325-8071 (Print)   ISSN 2325-808X (Online)

Copyright © Redfame Publishing Inc.

To make sure that you can receive messages from us, please add the 'redfame.com' domain to your e-mail 'safe list'. If you do not receive e-mail in your 'inbox', check your 'bulk mail' or 'junk mail' folders.

If you have any questions, please contact: [email protected]

------------------------------------------------------------------------------------------------------------------------------------------------------