Scan results

    iMobile: Loan, Cards & Banking

    Android

    iMobile is ICICI Bank's official mobile banking app offering 400+ services including instant loans, savings accounts, fund transfers, credit cards, bill payments, and investments with features like pre-approved loans, multi-card management, and rewards.

    CITT SCORE
    40
    out of 100
    unTRUSTED

    Quick Verdict

    Best for: ICICI customers comfortable with extensive analytics

    Not For: You prefer minimal data sharing with third parties

    What It Means For You

    Banking activity, device identifiers, and behavior patterns are shared with multiple analytics and marketing platforms including Firebase, AppsFlyer, Mixpanel, CleverTap, and Adobe. Usage habits are tracked across sessions to build a profile used for targeted engagement. Network protections are limited in some areas, which may affect how safely financial data travels.

    Method and Limitations

    Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.

    How CITT scores an app

    Findings (33)

    Data Security

    9 total
    1 Critical
    4 High
    4 Medium

    Network Security

    1 total
    1 Critical

    Code Security

    13 total
    2 Critical
    1 High
    4 Medium
    6 Low

    Privacy

    9 total
    4 High
    4 Medium
    1 Low

    Third-Party Risk

    1 total
    1 Low

    Third-Party Services

    Firebase Analytics, AppsFlyer, Adobe Campaign Classic, Smartech/Netcore, Mixpanel, Dynatrace, CleverTap, BioCatch, Nuclei SDK, Xtify SDK, Google Play SafetyNet, Google Play Integrity API, Visa SDK, Mastercard SDK, Comviva HCE

    Security Strengths

    • Certificate pinning implemented
    • Root detection via BioCatch and Play Integrity API
    • OAuth tokens stored in-memory only (not persisted to disk)
    • Android backup disabled
    • Production-grade code obfuscation
    What changed since the last scan

    Version diff is on the Developer plan. See developer plans.

    Context Tags

    financial
    sensitive data
    location
    ads
    biometric
    banking
    compliance risk

    Package

    com.csam.icici.bank.imobile

    Version

    28.1 (Build 463)

    Analysis Date

    Jan 27, 2026

    Classes Analyzed

    27,334

    Was this analysis helpful?

    Feedback helps us improve our analysis

    View on Play Store

    Recommendation: Use With Caution

    Key Findings

    Data Security - 9 findings (1 critical, 4 high, 4 medium)

    Network Security - 1 finding (1 critical)

    Code Safety - 0 findings

    Privacy - 9 findings (4 high, 4 medium, 1 low)

    Privacy Concerns

    What Data is Collected

    Device identifiers, behavioral patterns, session activity, and location signals are collected during use of the app. Each session generates data points retained by multiple platforms to build a picture of usage habits over time.

    Third-Party Data Sharing

    Data is shared with the following third-party services:

    • Firebase Analytics
    • AppsFlyer
    • Mixpanel
    • CleverTap
    • Adobe Campaign Classic
    • Smartech/Netcore
    • Dynatrace
    • BioCatch
    • Nuclei SDK
    • Xtify SDK
    • Google Play SafetyNet
    • Google Play Integrity API
    • Visa SDK
    • Mastercard SDK
    • Comviva HCE

    Understanding the Scores

    • Security: 42/100
    • Privacy: 38/100
    • Data Security: 45/100
    • Network Security: 35/100
    • Code Safety: 40/100
    • Data Collection: 30/100
    • Data Sharing: 35/100
    • User Control: 45/100

    Positive Security Features

    • No notable positive security features were identified in this version of the app.

    Areas for Improvement

    • Network communication limitations mean financial data may travel with less protection than expected.
    • The number of third-party analytics and marketing platforms receiving user data is unusually high for a financial app, leaving users with limited practical control over how that data is used.
    • Data collection scope extends well beyond what is needed to deliver core features, contributing to a broad behavioral profile built from session activity.

    About This Analysis

    This scorecard is generated from automated static analysis of the app's code and configuration. It reflects security and privacy practices observed at the time of the scan and is intended to help users make an informed decision about whether to use the app.

    App Details

    • App: iMobile: Loan, Cards & Banking
    • Package ID: com.csam.icici.bank.imobile
    • Version: 28.1 (Build 463)
    • Scan Date: 2026-01-27

    Right of Reply

    Developer not yet contacted