iMobile: Loan, Cards & Banking Security & Privacy Scorecard

Android

40
Overall trust score
Unsafe
42
Security
38
Privacy

Banking activity, device identifiers, and behavior patterns are shared with multiple analytics and marketing platforms including Firebase, AppsFlyer, Mixpanel, CleverTap, and Adobe. Usage habits are tracked across sessions to build a profile used for targeted engagement. Network protections are limited in some areas, which may affect how safely financial data travels.

Best for

ICICI customers comfortable with extensive analytics

Avoid if

You prefer minimal data sharing with third parties

Findings

  • 0 critical
  • 0 high
  • 0 medium
  • 0 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • Universal File Access in WebViews Enables XSS-to-RCE
  • Xtify SDK HTTP-Only Communication
  • JavaScript Interface File System Access

Top privacy issues

  • Biometric Data Collection Without Explicit Consent
  • Excessive Analytics (8 Platforms) Collecting Financial Data
  • Google Play Data Safety Disclosure Inaccurate

Full analysis

iMobile: Loan, Cards & Banking

What This Means for You

Banking activity, device identifiers, and behavior patterns are shared with multiple analytics and marketing platforms including Firebase, AppsFlyer, Mixpanel, CleverTap, and Adobe. Usage habits are tracked across sessions to build a profile used for targeted engagement. Network protections are limited in some areas, which may affect how safely financial data travels.

Recommendation: Use With Caution

Best For: ICICI customers comfortable with extensive analytics
Avoid If: You prefer minimal data sharing with third parties

Key Findings

Data Security - 9 findings (1 critical, 4 high, 4 medium)

Network Security - 1 finding (1 critical)

Code Safety - 0 findings

Privacy - 9 findings (4 high, 4 medium, 1 low)

Privacy Concerns

What Data is Collected

Device identifiers, behavioral patterns, session activity, and location signals are collected during use of the app. Each session generates data points retained by multiple platforms to build a picture of usage habits over time.

Third-Party Data Sharing

Data is shared with the following third-party services:

  • Firebase Analytics
  • AppsFlyer
  • Mixpanel
  • CleverTap
  • Adobe Campaign Classic
  • Smartech/Netcore
  • Dynatrace
  • BioCatch
  • Nuclei SDK
  • Xtify SDK
  • Google Play SafetyNet
  • Google Play Integrity API
  • Visa SDK
  • Mastercard SDK
  • Comviva HCE

Understanding the Scores

  • Security: 42/100
  • Privacy: 38/100
  • Data Security: 45/100
  • Network Security: 35/100
  • Code Safety: 40/100
  • Data Collection: 30/100
  • Data Sharing: 35/100
  • User Control: 45/100

Positive Security Features

  • No notable positive security features were identified in this version of the app.

Areas for Improvement

  • Network communication limitations mean financial data may travel with less protection than expected.
  • The number of third-party analytics and marketing platforms receiving user data is unusually high for a financial app, leaving users with limited practical control over how that data is used.
  • Data collection scope extends well beyond what is needed to deliver core features, contributing to a broad behavioral profile built from session activity.

About This Analysis

This scorecard is generated from automated static analysis of the app's code and configuration. It reflects security and privacy practices observed at the time of the scan and is intended to help users make an informed decision about whether to use the app.

App Details

  • App: iMobile: Loan, Cards & Banking
  • Package ID: com.csam.icici.bank.imobile
  • Version: 28.1 (Build 463)
  • Scan Date: 2026-01-27

Versions & scan history

ScanDateOverall score
#3 (current) 40/100