Okta Verify
- Known vulnerabilities
- 0
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- —
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Based on permissions only: no CVE data referenced for this app.
Known vulnerabilities (CVE)
No CVE is currently referenced in NVD for this app on its platform.
The absence of CVEs is not a security guarantee — it can also mean nobody has audited or published findings.
Context
Context
Description
Okta Verify is a lightweight app that is used for 2-step verification so you can confirm your identity when you sign in to your Okta account. This gives you an extra layer of security so that you - and only you - can access your applications. When you sign in to Okta, you can use Okta Verify to obtain a temporary 6-digit code or to approve a request notification sent to your device (your organization must enable notifications to use this feature). Okta values your privacy. Okta Verify does not store personal information - we request permission only for your device camera, which is used to scan a QR code to register your device with Okta. App Features * Enroll in Okta Verify as a new user by registering your mobile device with your Okta account. * Add one or more Okta accounts that require Okta Verify for authentication. * Manage 2-factor authentication for non-Okta applications and web services that require the use of passcodes. * Approve or deny sign-in requests on your device from a push notification (if enabled). For more information, check out our docs at: https://help.okta.com/en/prod/okta_help_CSH.htm#ext_okta_verify
Data collected and shared
Source: App Store · App Privacy · 4 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
FAQ
FAQ: Okta Verify
Why are no CVEs listed for Okta Verify?
No CVE is currently referenced in NVD for Okta Verify (com.okta.mobile) with a iOS CPE configuration. Either none has been publicly disclosed, or none has been mapped yet. Absence of a CVE is not a security guarantee.
What is the latest known version of Okta Verify?
The most recent version of Okta Verify (com.okta.mobile) tracked by Appaloosa Scout is 9.68.0, published by Okta, Inc..