Session token stored in plain text on the device
- Weakness
- CWE-312
- Where
- Android app, local preferences file
- Impact
- Anyone with access to a backup or a compromised device could reuse the session.
- Fix
- Keep tokens in the Android Keystore or iOS Keychain, and shorten their lifetime.









