Scan results

    CommBank

    Android

    Australia's best banking app with 16 years of top ratings. Bank on the go, manage accounts, transfer money, pay bills, and use digital wallets with advanced security features.

    CITT SCORE
    86
    out of 100
    TRUSTED

    Quick Verdict

    Best for: CommBank customers wanting mobile banking

    What It Means For You

    App usage and behaviour are monitored for fraud detection using behavioural biometrics. Analytics tools collect data on how users interact with the app, shared with Adobe and Splunk. Third-party data sharing is minimal, and users retain reasonable control over their information.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (23)

    Data Security

    6 total
    2 Medium
    3 Low
    1 Info

    Network Security

    5 total
    2 Medium
    2 Low
    1 Info

    Code Security

    6 total
    2 Medium
    2 Low
    2 Info

    Privacy

    3 total
    1 Medium
    1 Low
    1 Info

    Third-Party Risk

    1 total
    1 Info

    Permission Usage

    2 total
    1 Low
    1 Info

    Third-Party Services

    BioCatch (behavioral biometrics, fraud detection), Daon FIDO / DMDS (FIDO2 biometric auth, document scan), MicroBlink BlinkID (document/ID scanning, OCR), G+D CP Client (NFC HCE tokenisation, tap-to-pay), ID R&D IDLive Face (face liveness detection), Splunk MINT (crash reporting, event logging), Adobe Analytics / AEP Edge (app usage analytics), Firebase FCM (push notifications), Qt5 (embedded UI framework), SCUBA Smart Cards (NFC/ISO 7816 for passport/ID reading)

    Security Strengths

    • Custom certificate whitelist (KIA) with bundled initial pin set, signed remote updates, and getSslPinningEnabled()=true in all production Dagger bindings
    • G+D CP Client uses Android KeyStore (hardware-backed) with server-provisioned keys for NFC payment key storage
    • BioCatch consent gate correctly implemented — SDK not started until explicit user consent granted
    • Comprehensive backup exclusion (allowBackup=false) with explicit backup rules preventing data extraction
    • All primary API endpoints (authentication, transactions, payments) use HTTPS
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    biometrics
    location
    contacts

    Package

    com.commbank.netbank

    Version

    5.48.1.2576

    Analysis Date

    Mar 29, 2026

    Classes Analyzed

    68,671

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Trustworthy

    Key Findings

    Data Security - 6 findings (2 medium, 3 low, 1 info)

    Network Security - 5 findings (2 medium, 2 low, 1 info)

    Code Safety - 0 findings

    Privacy - 3 findings (1 medium, 1 low, 1 info)

    Privacy Concerns

    What Data is Collected

    • Behavioural patterns and interaction data collected for fraud detection
    • Biometric data used for authentication and identity verification
    • Crash reports and app usage events
    • Device identifiers for push notifications
    • Document and identity scan data during verification flows

    Third-Party Data Sharing

    Data is shared with a limited number of third-party services:

    • BioCatch - receives behavioural interaction data for fraud detection
    • Adobe Analytics - receives app usage and interaction data
    • Splunk MINT - receives crash reports and performance event data
    • Firebase FCM - receives device identifiers for push notifications
    • Daon / ID R&D - receives biometric data during authentication flows

    Understanding the Scores

    CategoryScore
    Security85/100
    Privacy87/100
    Data Security65/100
    Network Security83/100
    Code Safety85/100
    Data Collection83/100
    Data Sharing92/100
    User Control83/100

    Positive Security Features

    • Biometric authentication built on FIDO2 standards protects accounts from unauthorised access
    • Continuous behavioural monitoring works silently in the background to detect fraud before it impacts users
    • NFC-based secure payment handling supports safe tap-to-pay transactions
    • Liveness detection during identity checks helps prevent spoofing during onboarding and verification

    Areas for Improvement

    • Some data stored on the device could be better isolated from other apps installed on the same device.
    • Network communications could be more consistently hardened to reduce exposure on untrusted Wi-Fi networks.
    • Clearer in-app disclosure about which third-party services receive behavioural and usage data would give users better visibility into how their information is shared.

    About This Analysis

    This scorecard is based on automated static analysis of the app binary. Scores reflect the security and privacy posture of the app as shipped, not the developer's server-side practices.

    App Details

    FieldValue
    Packagecom.commbank.netbank
    Version5.48.1.2576
    Scan Date2026-03-29
    PlatformAndroid

    Right of Reply

    Developer not yet contacted