Offer

Free security assessment — you only subscribe if we find a P0 or P1 vulnerability.

Claim free assessment
CyVigilant
All case studies
Digital Health & Telemedicine

Inside a telehealth app: from hidden secrets to a full attack path

A national telehealth platform engaged CyVigilant for a manual, exploit-led assessment of its patient mobile app and supporting APIs ahead of a key compliance milestone. Where automated scanners had surfaced little, expert-led testing uncovered a chain of critical flaws — from secrets baked into the app to broken access controls — all responsibly reported, fixed, and retested to closure.

100%Criticals fixed & retested
9 Critical13 High10 Medium5 Low
Mobile Application VAPTAPI SecurityCloud Security Review
The Challenge

A fast-scaling digital-health provider handling sensitive patient information and in-app payments needed independent assurance before a regulatory audit. Routine vulnerability scanners had returned a near-clean result, but the security team suspected deeper, mobile-specific and business-logic risks that automated tools could not reach.

Our Approach

CyVigilant ran a manual, exploit-led VAPT across the patient Android app and its backend APIs in a controlled, authorised environment, across five phases:

  • Static analysis of the mobile binary and its embedded configuration
  • API and endpoint mapping
  • Dynamic runtime testing on an instrumented device
  • Live traffic interception and analysis
  • A server-side and cloud-configuration review

Every finding was validated with a safe, controlled proof-of-concept — never a “the scanner flagged it” result.

Findings

The assessment confirmed a chain of high-impact issues that automated tools missed, including:

  • Hardcoded credentials and secrets embedded in the mobile app
  • Broken object-level authorisation (IDOR) exposing other users' records
  • Server-side request forgery (SSRF) reaching internal cloud metadata and credentials
  • Injection flaws in the API layer
  • Overly permissive CORS with missing rate limiting

Chained together, these created a realistic path from an ordinary app user to sensitive data and internal infrastructure.

Outcome

CyVigilant delivered a prioritised, developer-ready remediation plan with CVSS-scored findings and reproducible steps. Secrets were rotated, access controls redesigned, and the API surface hardened.

Every critical and high issue was fixed and retested to closure within the agreed SLA — and the platform went on to pass its compliance audit. The engagement showed why expert-led, exploit-driven testing finds what scanners structurally cannot.

Results
9
Critical issues closed
100%
Retested to closure
< 4 wks
Report to all-criticals-fixed
0
Found by prior automated scans
Get started

Find what your scanners are missing.

Book a scoping call with an expert and get an exploit-led assessment of your own stack.

Talk to an Expert