Skip to content
Appaloosa Scout

Methodology & transparency

About Appaloosa Scout

An initiative by Appaloosa (OB2J SAS), French publisher of sovereign MDM/EMM solutions.

SecNumCloud / ANSSI compatible, GDPR-native. All data flows handled exclusively in France.

Methodology

  1. 01

    Coverage

    Only CVEs publicly referenced in NVD (NIST) with a CPE configuration tagged iphone_os, ipados, android, macos or windows are listed. The desktop catalog is sourced from Mac App Store + Homebrew (macOS) and Microsoft Store + winget (Windows).

    The absence of CVEs is not a security guarantee: many mobile app vulnerabilities are never published to NVD.

  2. 02

    CPE → bundle ID matching

    The mapping between NVD CPE identifiers and App Store / Play Store bundle IDs relies on a curated mapping (versioned in git) extended by automatic store-verified inference.

    False negatives possible if an app is not yet mapped; the page stays empty rather than making false associations.

  3. 03

    OS-level coverage

    Scout ingests five official advisory feeds: Apple Security Releases (iOS, iPadOS, macOS), Android Security Bulletin, MSRC (Windows / Patch Tuesday), Chrome Releases and MFSA Mozilla. Each CVE is indexed alongside the OS or app version that fixes it, and surfaces on the matching page (/os/ios/26.2, /os/android/2026-03-01, /os/windows/…). Until NVD publishes full metadata, these entries are flagged as "stubs" with a link back to the original source.

  4. 04

    Enrichment signals

    Beyond NVD and CISA KEV, Scout aggregates several signals to qualify each CVE: EPSS (FIRST.org) for the 30-day exploitation probability, VulnCheck Community KEV which extends the CISA catalog to vendor-reported exploits, OSV.dev for CVE ↔ package cross-references, endoflife.date for OS / app support status, Exodus Privacy for third-party trackers embedded in Android APKs, and HackerOne Hacktivity for publisher-disclosed bug bounty reports.

  5. 05

    Version history

    For each app, Scout rebuilds the version history and official release dates whenever a public source allows it. iOS: 25 most recent versions via apps.apple.com HTML (serialized-server-data script) + iTunes Lookup fallback. macOS Mac App Store: same source. winget: commits from microsoft/winget-pkgs. Homebrew: commits from homebrew-cask / homebrew-core. Versions enriched this way carry a badge indicating their source.

    Android (Google Play) and Microsoft Store: no public source exposes the history. For these 2 platforms, we only capture the current version observed by our crawler. The history is built going forward only, with no retroactive backfill.

  6. 06

    Data licenses

    NVD is public domain, CISA KEV is CC0. Source cited on every record. No hidden reprocessing.

Update frequency

Hourly
NVD sync
2 h sliding window
Daily
CISA KEV
06:00 UTC, full sync
Daily
OS-level advisories
Apple, Android, MSRC, Chrome, Mozilla
Daily
Enrichment signals
EPSS, VulnCheck KEV, OSV.dev, endoflife.date
Weekly
App enrichment
App Store, Play Store, Mac App Store, Microsoft Store, winget, Homebrew
Weekly
Icon refresh
256×256 PNG

Use cases

MDM admin

Quickly check which CVEs concern the managed apps in your fleet.

CISO

Track CISA KEV CVEs affecting the enterprise mobile ecosystem.

Research

Explore the landscape of publicly recognized mobile vulnerabilities.

Published by

Appaloosa, the publisher

Appaloosa provides a complete French MDM/EMM platform: public and private app distribution, iOS / Android / macOS / Windows device management, compliance, mass deployments.

Discover Appaloosa MDM