A study of mobile banking applications conducted by security researcher Sanchez showed that:
12.5% of the examined applications did not verify the authenticity of SSL certificates, which makes them vulnerable to Man-in-the-Middle (MITM) attacks,
35% of the applications that contain non-SSL links at . This allows an attacker to hijack the traffic and inject arbitrary JavaScript/HTML code, in an attempt to create fake login prompts or similar scams,
30% of the applications examined did not validate incoming data and were vulnerable to JavaScript injections via insecure UIWebView applications, thus allowing the so‑called client‑side attacks ,
42.5% of these applications provided alternative authentication solutions to mitigate the risk of user credential leakage and impersonal attacks.
40% of apps still leak information about user activity or client‑server interactions, such as requests / responses from the server.
This study was followed by a research conducted by Sanchez in January 2014, whose findings show that the security issue has expanded in recent years, as 15% of apps have jailbreak protection to detect and advise users regarding the risks of jailbroken devices.
Nevertheless, 15% of the applications examined store unencrypted sensitive information in the file system via SQLite databases or other plaintext files. Sanchez states that after two years since he conducted his research, the majority of apps have raised the level of transport security of the data by using SSL certificates or by eliminating plain-text traffic. However, there is still a large number of apps that store sensitive information and data in their file system and remain vulnerable to client-side attacks.

