Skip to content
Appaloosa Scout

Annual recap

Mobile security · 2025

2025 review indexed by Appaloosa Scout: 2,203 mobile CVE published, 55 added to the CISA KEV catalog (exploited in real attacks), 6 mobile apps affected by at least one KEV.

See multi-year trends in the Threat Observatory

CVE indexed this year
2,203
CISA KEV added
55
Tracked apps affected
6

Severity distribution

CRITICAL 216
HIGH 1,471
MEDIUM 465
LOW 51

Top 10 mobile KEV of the year

Sorted by number of mobile apps affected (CVSS as tiebreaker).

CVE Severity
CVE-2025-48384
2 apps
HIGH 8.0
CVE-2010-3765
1 apps
CRITICAL 9.8
CVE-2025-8088
1 apps
HIGH 8.8
CVE-2025-6218
1 apps
HIGH 7.8
CVE-2025-0411
1 apps
HIGH 7.0
CVE-2025-55177
1 apps
MEDIUM 5.4
CVE-2025-43300
0 apps
CRITICAL 10.0
CVE-2025-32433
0 apps
CRITICAL 10.0
CVE-2025-24201
0 apps
CRITICAL 10.0
CVE-2025-24085
0 apps
CRITICAL 10.0

Top vendors by KEV this year

  1. 1 win.rar GmbH 2 KEV · 1 apps
  2. 2 Apple Distribution International 1 KEV · 1 apps
  3. 3 Igor Pavlov 1 KEV · 1 apps
  4. 4 Mozilla 1 KEV · 1 apps
  5. 5 The Git Development Community 1 KEV · 1 apps
  6. 6 WhatsApp Inc. 1 KEV · 1 apps

Most affected apps

Methodology

KEV: added to the CISA catalog during the year (kev_added_date). CVE: NVD publication date. Apps: those indexed in Scout at query time; the history evolves as new mappings are added.