Movatterモバイル変換


[0]ホーム

URL:


MASVS-PLATFORM

Checklists Updated (June 2025)

The checklists now includeall MASTG tests, as well as updated mappings to the newMAS profiles.

MASVS-IDMASTG-TEST-IDControl / MASTG TestPlatformL1L2RPStatus
MASVS-PLATFORM-1The app uses IPC mechanisms securely.
MASTG-TEST-0028 Testing Deep Linksplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0007 Determining Whether Sensitive Stored Data Has Been Exposed via IPC Mechanismsplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0029 Testing for Sensitive Functionality Exposure Through IPCplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0024 Testing for App Permissionsplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0030 Testing for Vulnerable Implementation of PendingIntentplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0069 Testing App Permissionsplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0072 Testing App Extensionsplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0070 Testing Universal Linksplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0075 Testing Custom URL Schemesplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0073 Testing UIPasteboardplatform:iosprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0056 Determining Whether Sensitive Data Is Exposed via IPC Mechanismsplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0071 Testing UIActivity Sharingplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASVS-PLATFORM-2The app uses WebViews securely.
MASTG-TEST-0033 Testing for Java Objects Exposed Through WebViewsplatform:androidprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0037 Testing WebViews Cleanupplatform:androidprofile:L2update-pendingstatus:update-pending
MASTG-TEST-0250 References to Content Provider Access in WebViewsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0251 Runtime Use of Content Provider Access APIs in WebViewsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0252 References to Local File Access in WebViewsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0253 Runtime Use of Local File Access APIs in WebViewsplatform:androidprofile:L1profile:L2newstatus:new
MASTG-TEST-0031 Testing JavaScript Execution in WebViewsplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0032 Testing WebView Protocol Handlersplatform:androidprofile:L1profile:L2deprecatedstatus:deprecated
MASTG-TEST-0076 Testing iOS WebViewsplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0078 Determining Whether Native Methods Are Exposed Through WebViewsplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASTG-TEST-0077 Testing WebView Protocol Handlersplatform:iosprofile:L1profile:L2update-pendingstatus:update-pending
MASVS-PLATFORM-3The app uses the user interface securely.
MASTG-TEST-0008 Checking for Sensitive Data Disclosure Through the User Interfaceplatform:androidprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0289 Runtime Verification of Sensitive Content Exposure in Screenshots During App Backgroundingplatform:androidprofile:L2newstatus:new
MASTG-TEST-0291 References to Screen Capturing Prevention APIsplatform:androidprofile:L2newstatus:new
MASTG-TEST-0315 Sensitive Data Exposed via Notificationsplatform:androidprofile:L2newstatus:new
MASTG-TEST-0293setSecure Not Used to Prevent Screenshots in SurfaceViewsplatform:androidprofile:L2placeholderstatus:placeholder
MASTG-TEST-0294SecureOn Not Used to Prevent Screenshots in Compose Dialogsplatform:androidprofile:L2placeholderstatus:placeholder
MASTG-TEST-0010 Finding Sensitive Information in Auto-Generated Screenshotsplatform:androidprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0316 App Exposing User Authentication Data in Text Input Fieldsplatform:androidprofile:L2newstatus:new
MASTG-TEST-0035 Testing for Overlay Attacksplatform:androidprofile:L2update-pendingstatus:update-pending
MASTG-TEST-0258 References to Keyboard Caching Attributes in UI Elementsplatform:androidprofile:L2newstatus:new
MASTG-TEST-0292setRecentsScreenshotEnabled Not Used to Prevent Screenshots When Backgroundedplatform:androidprofile:L2placeholderstatus:placeholder
MASTG-TEST-0314 Runtime Monitoring of Text Fields Eligible for Keyboard Cachingplatform:iosprofile:L2newstatus:new
MASTG-TEST-0313 References to APIs for Preventing Keyboard Caching of Text Fieldsplatform:iosprofile:L2newstatus:new
MASTG-TEST-0276 Use of the iOS General Pasteboardplatform:iosprofile:L2newstatus:new
MASTG-TEST-0279 Pasteboard Contents Not Expiringplatform:iosprofile:L2newstatus:new
MASTG-TEST-0059 Testing Auto-Generated Screenshots for Sensitive Informationplatform:iosprofile:L2deprecatedstatus:deprecated
MASTG-TEST-0278 Pasteboard Contents Not Cleared After Useplatform:iosprofile:L2newstatus:new
MASTG-TEST-0280 Pasteboard Contents Not Restricted to Local Deviceplatform:iosprofile:L2newstatus:new
MASTG-TEST-0057 Checking for Sensitive Data Disclosed Through the User Interfaceplatform:iosprofile:L2update-pendingstatus:update-pending
MASTG-TEST-0277 Sensitive Data in the iOS General Pasteboard at Runtimeplatform:iosprofile:L2newstatus:new
MASTG-TEST-0290 Runtime Verification of Sensitive Content Exposure in Screenshots During App Backgroundingplatform:iosprofile:L2newstatus:new





[8]ページ先頭

©2009-2025 Movatter.jp