iMobile: Loan, Cards & Banking Security & Privacy Scorecard
Android
Banking activity, device identifiers, and behavior patterns are shared with multiple analytics and marketing platforms including Firebase, AppsFlyer, Mixpanel, CleverTap, and Adobe. Usage habits are tracked across sessions to build a profile used for targeted engagement. Network protections are limited in some areas, which may affect how safely financial data travels.
Best for
ICICI customers comfortable with extensive analytics
Avoid if
You prefer minimal data sharing with third parties
Findings
- 0 critical
- 0 high
- 0 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Universal File Access in WebViews Enables XSS-to-RCE
- Xtify SDK HTTP-Only Communication
- JavaScript Interface File System Access
Top privacy issues
- Biometric Data Collection Without Explicit Consent
- Excessive Analytics (8 Platforms) Collecting Financial Data
- Google Play Data Safety Disclosure Inaccurate
Full analysis
iMobile: Loan, Cards & Banking
What This Means for You
Banking activity, device identifiers, and behavior patterns are shared with multiple analytics and marketing platforms including Firebase, AppsFlyer, Mixpanel, CleverTap, and Adobe. Usage habits are tracked across sessions to build a profile used for targeted engagement. Network protections are limited in some areas, which may affect how safely financial data travels.
Recommendation: Use With Caution
Best For: ICICI customers comfortable with extensive analytics
Avoid If: You prefer minimal data sharing with third parties
Key Findings
Data Security - 9 findings (1 critical, 4 high, 4 medium)
Network Security - 1 finding (1 critical)
Code Safety - 0 findings
Privacy - 9 findings (4 high, 4 medium, 1 low)
Privacy Concerns
What Data is Collected
Device identifiers, behavioral patterns, session activity, and location signals are collected during use of the app. Each session generates data points retained by multiple platforms to build a picture of usage habits over time.
Third-Party Data Sharing
Data is shared with the following third-party services:
- Firebase Analytics
- AppsFlyer
- Mixpanel
- CleverTap
- Adobe Campaign Classic
- Smartech/Netcore
- Dynatrace
- BioCatch
- Nuclei SDK
- Xtify SDK
- Google Play SafetyNet
- Google Play Integrity API
- Visa SDK
- Mastercard SDK
- Comviva HCE
Understanding the Scores
- Security: 42/100
- Privacy: 38/100
- Data Security: 45/100
- Network Security: 35/100
- Code Safety: 40/100
- Data Collection: 30/100
- Data Sharing: 35/100
- User Control: 45/100
Positive Security Features
- No notable positive security features were identified in this version of the app.
Areas for Improvement
- Network communication limitations mean financial data may travel with less protection than expected.
- The number of third-party analytics and marketing platforms receiving user data is unusually high for a financial app, leaving users with limited practical control over how that data is used.
- Data collection scope extends well beyond what is needed to deliver core features, contributing to a broad behavioral profile built from session activity.
About This Analysis
This scorecard is generated from automated static analysis of the app's code and configuration. It reflects security and privacy practices observed at the time of the scan and is intended to help users make an informed decision about whether to use the app.
App Details
- App: iMobile: Loan, Cards & Banking
- Package ID: com.csam.icici.bank.imobile
- Version: 28.1 (Build 463)
- Scan Date: 2026-01-27
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 40/100 |