Adversaries may exploit software vulnerabilities to gain initial access to a mobile device. This can be accomplished in a variety of ways. Vulnerabilities may be present in the applications, the services, the underlying operating system, or the kernel itself. Several well-known mobile device exploits exist, including FORCEDENTRY, StageFright, and BlueBorne. Furthermore, some exploits may be possible to exploit without any user interaction (i.e. zero-click exploits, see [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1658)), making them particularly dangerous. Mobile operating system vendors are typically very quick to patch such critical bugs, ensuring only a small window where they can be exploited.
Install security updates in response to discovered vulnerabilities. Purchase devices with a vendor and/or mobile carrier commitment to provide security updates in a prompt manner for a set period of time. Decommission devices that will no longer receive security updates. Limit or block access to enterprise resources from devices that have not installed recent security updates. On Android devices, access can be controlled based on each device's security patch level. On iOS devices, access can be controlled based on the iOS version.
M1058Antivirus/AntimalwareMobile security products, such as Mobile Threat Defense (MTD), offer various device-based mitigations against certain behaviors.
MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.