Lookout adds mobile app code exposure scanning to endpoint platform
Lookout’s new tool analyzes Android and iOS app binaries to flag vulnerable third-party code across enterprise mobile fleets.
By Colin Brandt · Enterprise Reporter
· 3 min read
Lookout has launched Mobile Software Exposure Center, a capability inside its Mobile Endpoint Security platform that scans mobile apps on employee devices for vulnerable embedded code. Pricing, revenue impact and customer adoption figures were not disclosed, but the release extends Lookout’s endpoint product into mobile software supply-chain visibility, an area the company says conventional enterprise security tooling misses.
The product is delivered through the same Lookout console and device agent already used by customers, according to the company. That matters for security teams that have mobile fleets under management but lack visibility into the libraries, software development kits and external APIs bundled into the apps employees install and use.
Lookout’s pitch is that mobile device management products can enforce device and app policies, but they do not inspect what is inside an application package. The company says that gap has become more relevant as enterprise mobile apps increasingly depend on open-source components and third-party SDKs, any of which can carry known vulnerabilities or become stale when vendors stop maintaining them.
Binary analysis without source code
Mobile Software Exposure Center analyzes Android and iOS applications at the compiled binary level, according to Lookout. The company says the tool does not require access to source code. Instead, it identifies code fingerprints, generates a software bill of materials for each app and checks discovered components against Common Vulnerabilities and Exposures databases as well as third-party threat intelligence feeds.
The system is designed to flag vulnerable SDKs, outdated libraries and other components that may expose a company’s mobile environment. Security teams can search across a device fleet to identify which apps contain a specific component, then use existing mobile device management or unified endpoint management workflows to restrict applications deemed risky, Lookout said.
The product also scores apps for signs of poor maintenance, including abandonment and patching hygiene. Lookout did not disclose the scoring methodology or how it weighs different vulnerability sources, which will be relevant for customers trying to avoid another noisy alert feed inside the security stack.
AI claims frame the launch
Lookout tied the release to the availability of frontier AI models, including Anthropic’s Claude Fable 5 and Mythos 5. The company argues that advanced models shorten the time required to find exploitable bugs in mobile applications from months to hours. That is a serious claim, though Lookout did not provide benchmark data in the announcement to quantify the reduction.
As supporting context, Lookout pointed to its Threat Labs discovery in March of DarkSword, an iOS exploit chain that it said targeted flaws hidden in legitimate apps. The company presents that case as evidence that attackers are already seeking weaknesses in mobile app internals rather than relying only on traditional malware.
Chief Executive Jim Dolce said in the announcement that automated exploitation changes the risk model for mobile security and that inspecting application binaries at speed gives enterprises control points for finding hidden vulnerabilities before they are used against corporate environments.
The new release follows Lookout’s April launch of AI Visibility and Governance, a product aimed at finding and managing AI usage from mobile devices. Mobile Software Exposure Center addresses a different side of the same managed-device problem: the code running on the handset rather than the services employees access from it.
Lookout says the new capability draws on more than 15 years of mobile threat research and telemetry from more than 235 million devices and 400 million applications. Existing customers can access the feature without deploying a new agent, according to the company.
This story draws on original reporting from SiliconANGLE.