Skip to content
Appaloosa Scout

Annual recap

Mobile security · 2022

2022 review indexed by Appaloosa Scout: 1 279 mobile CVE published, 84 added to the CISA KEV catalog (exploited in real attacks), 4 mobile apps affected by at least one KEV.

See multi-year trends in the Threat Observatory

CVE indexed this year
1 279
CISA KEV added
84
Tracked apps affected
4

Severity distribution

CRITICAL 122
HIGH 1 075
MEDIUM 79
LOW 2

Top 10 mobile KEV of the year

Sorted by number of mobile apps affected (CVSS as tiebreaker).

CVE Severity
CVE-2019-11708
1 apps
CRITICAL 10.0
CVE-2022-26486
1 apps
CRITICAL 9.6
CVE-2019-11707
1 apps
HIGH 8.8
CVE-2013-1690
1 apps
HIGH 8.8
CVE-2022-26485
1 apps
HIGH 8.8
CVE-2019-18426
1 apps
HIGH 8.2
CVE-2018-20250
1 apps
HIGH 7.8
CVE-2013-1675
1 apps
MEDIUM 6.5
CVE-2020-0796
0 apps
CRITICAL 10.0
CVE-2021-31166
0 apps
CRITICAL 9.8

Top vendors by KEV this year

  1. 1 Mozilla 6 KEV · 2 apps
  2. 2 WhatsApp Inc. 1 KEV · 1 apps
  3. 3 win.rar GmbH 1 KEV · 1 apps

Most affected apps

Methodology

KEV: added to the CISA catalog during the year (kev_added_date). CVE: NVD publication date. Apps: those indexed in Scout at query time; the history evolves as new mappings are added.