# Mobile Security Is Drowning in AI Bloat _Black Hat Asia 2026 Mobile Track panel says AI code bloat and Hermes monoculture are expanding mobile attack surface while hardware checks remain bypassable._ **Published:** 2026-09-03 **Source:** https://www.startuphub.ai/cybersecurity/mobile-security-is-drowning-in-ai-bloat --- AI code bloat, not a fresh exploit, is the defining problem at [BlackHat](https://www.youtube.com/watch?v=QZGwGYxYVCY) Asia 2026's mobile security spotlight. Three mobile track reviewers took the stage right after lunch for an open Q&A. Ansh Shrivastava of Siphonoid Research, Shana from Sydney's Torren Cyber Group, and Pamela O'Shea of Melbourne's mobile testing and code review firm ran it as a live clinic. ## How mobile security testing actually breaks The complaint was consistent. Clients ship React apps across platforms, and AI has made codebases balloon. Web apps can keep growing. Phones can't. One reviewer said the extra bulk will have to be clawed back, but for now reviewers face more code to cover in the same two week window. Progressive web apps aren't the escape hatch some expected. The panel said PWA momentum has stalled as teams consolidate on a single codebase. That codebase is increasingly React Native with Hermes. Performance used to hurt React Native, and Hermes compilation fixed much of that. So the same bug now ships everywhere at once. From a black box view that's also harder to reverse, which is why the panel asked clients to hand over source. AI in pentesting fits the same pattern. All three said they use it for coverage and pattern matching across huge repos, not for judgment. LLMs are strong on well documented, low hanging flaws because their training data is deep there. They struggle on business logic, thinly described API functions, and flows that need a payment, facial recognition, or a tap at a specific screen coordinate. One speaker said Android's best automation engine is still monkey, which just fires random clicks with no understanding of context. Aspect ratios and device specific UI make reliable automation brittle. ## Why hardware fixes are not enough The second thread was hardware backed security. Questions focused on Secure Enclave, Android StrongBox, and whether OEM mediated access helps. The panel said isolation is moving in the right direction. The boot ROM talk the prior day showed separate chips containing functions, so controlling one flow no longer means controlling the device. Even physical access is getting harder. Yet every few months another enclave bypass appears. The radio stack remains old and messy and keeps drawing research. The more durable point was architectural. Mobile has no trusted client. Unlike a server you control, the app lives on hostile territory 100% of the time, so every entry and exit has to be validated server side. That reframes common controls. Jailbreak detection, root checks, emulator checks, and SSL pinning against a leaf, intermediate, or root certificate are all bypassable with enough effort, including Play Integrity on Android and equivalent iOS checks. The panel framed it as a cost decision. Pin to the leaf and your shopping app needs a hash rotation every 90 days that users won't install. Skip checks and you may fail to warn a user they're on a rooted, outdated device that no longer gets patches. Banks will pay for long bypass times. A retailer may not. [Corellium](/startups/corellium) and similar device virtualization startups are filling this gap for testing precisely because real hardware fragmentation means a single policy never fits all users. --- Original analysis from [startuphub.ai](https://www.startuphub.ai), the #1 AI startup directory.