Inside a telehealth app: from hidden secrets to a full attack path
A national telehealth platform engaged CyVigilant for a manual, exploit-led assessment of its patient mobile app and supporting APIs ahead of a key compliance milestone. Where automated scanners had surfaced little, expert-led testing uncovered a chain of critical flaws — from secrets baked into the app to broken access controls — all responsibly reported, fixed, and retested to closure.
A fast-scaling digital-health provider handling sensitive patient information and in-app payments needed independent assurance before a regulatory audit. Routine vulnerability scanners had returned a near-clean result, but the security team suspected deeper, mobile-specific and business-logic risks that automated tools could not reach.
CyVigilant ran a manual, exploit-led VAPT across the patient Android app and its backend APIs in a controlled, authorised environment, across five phases:
- Static analysis of the mobile binary and its embedded configuration
- API and endpoint mapping
- Dynamic runtime testing on an instrumented device
- Live traffic interception and analysis
- A server-side and cloud-configuration review
Every finding was validated with a safe, controlled proof-of-concept — never a “the scanner flagged it” result.
The assessment confirmed a chain of high-impact issues that automated tools missed, including:
- Hardcoded credentials and secrets embedded in the mobile app
- Broken object-level authorisation (IDOR) exposing other users' records
- Server-side request forgery (SSRF) reaching internal cloud metadata and credentials
- Injection flaws in the API layer
- Overly permissive CORS with missing rate limiting
Chained together, these created a realistic path from an ordinary app user to sensitive data and internal infrastructure.
CyVigilant delivered a prioritised, developer-ready remediation plan with CVSS-scored findings and reproducible steps. Secrets were rotated, access controls redesigned, and the API surface hardened.
Every critical and high issue was fixed and retested to closure within the agreed SLA — and the platform went on to pass its compliance audit. The engagement showed why expert-led, exploit-driven testing finds what scanners structurally cannot.
Find what your scanners are missing.
Book a scoping call with an expert and get an exploit-led assessment of your own stack.
Talk to an Expert