Mobile devices present a serious security problem: they operate outside the security perimeter and beyond the visibility of the security team. While security may know what applications live on those devices, they rarely understand the components and dependencies that comprise those applications; nor what vulnerabilities are buried within those components.

Jim Dolce, CEO at Lookout, gave an example: WolfSSL. It’s a small, fast, and portable SSL/TLS library written in ANSI C, designed mainly for devices with limited memory – and it exists on more than a billion devices. “If you have a banking app on a mobile device for online banking, that app is likely using WolfSSL. It has a very serious vulnerability. If exploited by a bad actor, it can mimic your bank, and when you put in your credentials, it will steal your banking credentials.”

The Mythos Glasswing project found and publicized this WolfSSL vulnerability. So, the bad guys know the banking app may be vulnerable, but does the security team know that employees are using it?

“Knowing an application’s name and version reveals only a fraction of its risk profile,” explains Lookout. “Security teams need visibility into the software components, dependencies, and vulnerabilities embedded beneath the surface.”

This is what the firm’s new Mobile Security Exposure Center (MSEC) provides: full visibility into (rather simply ‘about’) an organization’s potentially vast mobile fleet. In a nutshell, MSEC examines every device in the fleet, so it knows what apps are present. It then creates its own proprietary software bill of materials (SBOM) from the binary for the different apps.

From this SBOM it learns every component within the app and correlates those components with the vulnerability databases (such as the KEV list) that exist. The results are fed into the organization’s CTEM to assist the security team to take any necessary remediation steps.

“The system will identify which apps use WolfSSL, the version of that app, the user and the device that is using that app, and all of that information then can be used to remediate the exposure. So MSEC basically identifies the exposure and provides that information,” continued Dolce. This applies to all the software components of all the apps on all the mobile devices.

MSEC also complements Lookout’s existing AI Visibility & Governance product. “While AI Visibility & Governance helps organizations understand AI adoption and usage across the enterprise,” says Lookout, “MSEC reveals the software composition and exposure profile of those applications. Together, they provide a more complete view of application risk, security, and governance.”

The result, it continues, is “A shift from reactive application management to proactive exposure management.”

However, there is a slight issue here. MSEC correlates the app components it unearths in its SBOM creation with the vulnerability databases that exist. We’ve mentioned one – the KEV list, or the Known Exploited Vulnerabilities Catalog produced by CISA. The clue to the issue is in the name, known vulnerabilities. No vulnerability database can include unknown vulnerabilities. So, while MSEC can help remediate known vulnerabilities, there is always the possibility that a new frontier AI model will unearth new vulnerabilities.

Lookout is obviously aware of this, and has it covered.

“Bad actors can use frontier AI models, Mythos as an example, in order to find vulnerabilities and exploit them,” agreed Dolce. “That’s the offensive use of a frontier AI model. Well, Lookout can use that same model defensively. We can go beyond KEV and the other vulnerability databases by using the frontier models ourselves to find unknown vulnerabilities across the SBOM. That will be the next iteration of MSEC.”

He continued, “We will take our SBOM and use the frontier AI models defensively to go and find unknown vulnerabilities for ourselves, and catalog those as well.”

But it all starts with knowing the app inventory across the enterprise mobile fleet, creating the accurate SBOM for all the apps in the fleet, and then correlating the app components against known vulnerability databases, and then, he added, “The last step is find unknown vulnerabilities using the same frontier AI models defensively that the bad guys are using offensively.”

Related: Mobile Attack Surface Expands as Enterprises Lose Control

Related: FBI Warns of Data Security Risks From China-Made Mobile Apps

Related: Mobile Security: Verizon Says Attacks Soar, AI-Powered Threats Raise Alarm

Related: Chinese Hackers Turn Smartphones Into a ‘Mobile Security Crisis’