Mobile Security Is Drowning in AI Bloat

Black Hat Asia 2026 Mobile Track panel says AI code bloat and Hermes monoculture are expanding mobile attack surface while hardware checks remain bypassable.

Black Hat Asia 2026 Mobile Track Spotlight panel discussing AI code bloat and hardware security
Review board members debate AI bloat, Hermes and Secure Enclave limits at Black Hat Asia 2026· BlackHat

AI code bloat, not a fresh exploit, is the defining problem at BlackHat Asia 2026's mobile security spotlight.

Mobile Security Is Drowning in AI Bloat - BlackHat
Mobile Security Is Drowning in AI Bloat, from BlackHat

Three mobile track reviewers took the stage right after lunch for an open Q&A. Ansh Shrivastava of Siphonoid Research, Shana from Sydney's Torren Cyber Group, and Pamela O'Shea of Melbourne's mobile testing and code review firm ran it as a live clinic.

How mobile security testing actually breaks

The complaint was consistent. Clients ship React apps across platforms, and AI has made codebases balloon.

Web apps can keep growing. Phones can't. One reviewer said the extra bulk will have to be clawed back, but for now reviewers face more code to cover in the same two week window.

Progressive web apps aren't the escape hatch some expected. The panel said PWA momentum has stalled as teams consolidate on a single codebase.

That codebase is increasingly React Native with Hermes. Performance used to hurt React Native, and Hermes compilation fixed much of that. So the same bug now ships everywhere at once. From a black box view that's also harder to reverse, which is why the panel asked clients to hand over source.

AI in pentesting fits the same pattern. All three said they use it for coverage and pattern matching across huge repos, not for judgment.

LLMs are strong on well documented, low hanging flaws because their training data is deep there. They struggle on business logic, thinly described API functions, and flows that need a payment, facial recognition, or a tap at a specific screen coordinate. One speaker said Android's best automation engine is still monkey, which just fires random clicks with no understanding of context. Aspect ratios and device specific UI make reliable automation brittle.

Why hardware fixes are not enough

The second thread was hardware backed security. Questions focused on Secure Enclave, Android StrongBox, and whether OEM mediated access helps.

The panel said isolation is moving in the right direction. The boot ROM talk the prior day showed separate chips containing functions, so controlling one flow no longer means controlling the device. Even physical access is getting harder.

Yet every few months another enclave bypass appears. The radio stack remains old and messy and keeps drawing research.

The more durable point was architectural. Mobile has no trusted client. Unlike a server you control, the app lives on hostile territory 100% of the time, so every entry and exit has to be validated server side.

That reframes common controls. Jailbreak detection, root checks, emulator checks, and SSL pinning against a leaf, intermediate, or root certificate are all bypassable with enough effort, including Play Integrity on Android and equivalent iOS checks. The panel framed it as a cost decision. Pin to the leaf and your shopping app needs a hash rotation every 90 days that users won't install. Skip checks and you may fail to warn a user they're on a rooted, outdated device that no longer gets patches. Banks will pay for long bypass times. A retailer may not. Corellium and similar device virtualization startups are filling this gap for testing precisely because real hardware fragmentation means a single policy never fits all users.

© 2026 StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training requires a license. See our terms.
Daniel Singer

Written by

Daniel Singer

Editor, StartupHub.ai

Daniel Singer is the editor of StartupHub.ai, a technology expert and thought leader on AI and its applications across sectors, from fintech and healthcare to developer tooling and consumer software. He writes and tests the tools covered here thoroughly and regularly, and built StartupHub.ai to give founders, operators and buyers a clearer read on what they are actually being sold.

More from Daniel Singer