Methodology & transparency
About Appaloosa Scout
An initiative by Appaloosa (OB2J SAS), French publisher of sovereign MDM/EMM solutions.
SecNumCloud / ANSSI compatible, GDPR-native. All data flows handled exclusively in France.
Methodology
-
01
Coverage
Only CVEs publicly referenced in NVD (NIST) with a CPE configuration tagged
iphone_os,ipados,android,macosorwindowsare listed. The desktop catalog is sourced from Mac App Store + Homebrew (macOS) and Microsoft Store + winget (Windows).The absence of CVEs is not a security guarantee: many mobile app vulnerabilities are never published to NVD.
-
02
CPE → bundle ID matching
The mapping between NVD CPE identifiers and App Store / Play Store bundle IDs relies on a curated mapping (versioned in git) extended by automatic store-verified inference.
False negatives possible if an app is not yet mapped; the page stays empty rather than making false associations.
-
03
OS-level coverage
Scout ingests five official advisory feeds: Apple Security Releases (iOS, iPadOS, macOS), Android Security Bulletin, MSRC (Windows / Patch Tuesday), Chrome Releases and MFSA Mozilla. Each CVE is indexed alongside the OS or app version that fixes it, and surfaces on the matching page (/os/ios/26.2, /os/android/2026-03-01, /os/windows/…). Until NVD publishes full metadata, these entries are flagged as "stubs" with a link back to the original source.
-
04
Enrichment signals
Beyond NVD and CISA KEV, Scout aggregates several signals to qualify each CVE: EPSS (FIRST.org) for the 30-day exploitation probability, VulnCheck Community KEV which extends the CISA catalog to vendor-reported exploits, OSV.dev for CVE ↔ package cross-references, endoflife.date for OS / app support status, Exodus Privacy for third-party trackers embedded in Android APKs, and HackerOne Hacktivity for publisher-disclosed bug bounty reports.
-
05
Version history
For each app, Scout rebuilds the version history and official release dates whenever a public source allows it. iOS: 25 most recent versions via
apps.apple.comHTML (serialized-server-datascript) + iTunes Lookup fallback. macOS Mac App Store: same source. winget: commits from microsoft/winget-pkgs. Homebrew: commits from homebrew-cask / homebrew-core. Versions enriched this way carry a badge indicating their source.Android (Google Play) and Microsoft Store: no public source exposes the history. For these 2 platforms, we only capture the current version observed by our crawler. The history is built going forward only, with no retroactive backfill.
-
06
Data licenses
NVD is public domain, CISA KEV is CC0. Source cited on every record. No hidden reprocessing.
Update frequency
- Hourly
-
NVD sync2 h sliding window
- Daily
-
CISA KEV06:00 UTC, full sync
- Daily
-
OS-level advisoriesApple, Android, MSRC, Chrome, Mozilla
- Daily
-
Enrichment signalsEPSS, VulnCheck KEV, OSV.dev, endoflife.date
- Weekly
-
App enrichmentApp Store, Play Store, Mac App Store, Microsoft Store, winget, Homebrew
- Weekly
-
Icon refresh256×256 PNG
Use cases
MDM admin
Quickly check which CVEs concern the managed apps in your fleet.
CISO
Track CISA KEV CVEs affecting the enterprise mobile ecosystem.
Research
Explore the landscape of publicly recognized mobile vulnerabilities.
Published by
Appaloosa, the publisher
Appaloosa provides a complete French MDM/EMM platform: public and private app distribution, iOS / Android / macOS / Windows device management, compliance, mass deployments.