Skip to content

[BUG] Mortgage calculator flagged for root/jailbreak detection #3

Description

@muneebahmedayub

Bug Description

False positive: Mortgage calculator flagged for root/jailbreak detection due to financial terminology in code, despite performing only mathematical calculations with no actual payment processing or sensitive data handling.

To Reproduce

Steps to reproduce the behavior:

  1. Run npx rnsec on a React Native project
  2. Have components with names/content containing keywords like "payment", "interest"
  3. Components only perform calculations (may call APIs for calculation logic, but no payment processing)
  4. See HIGH severity warning: "Sensitive app (banking/fintech/healthcare) without root/jailbreak detection"

Expected Behavior

The tool should differentiate between:

  1. Actual payment/financial transaction processing should flag for root detection
  2. Financial calculators/mathematical operations should not be flagged

Actual Behavior

Mortgage calculator components were flagged as HIGH severity requiring root/jailbreak detection based on keyword detection alone.

Environment

  • rnsec version: 1.0.0
  • Node version: v22.12.0
  • OS: macOS 26.0.1
  • Expo version: Expo SDK 54.0.1

Command Output

   HIGH  Sensitive app (banking/fintech/healthcare) without root/jailbreak detection                                   
      .../src/locales/index.ts:1                                                                                        

   HIGH  Sensitive app (banking/fintech/healthcare) without root/jailbreak detection                                   
      .../components/CalculatorForm/index.tsx:1                                                                         

   HIGH  Sensitive app (banking/fintech/healthcare) without root/jailbreak detection                                   
      .../components/CalculatorResult/index.tsx:1                                                                       

Additional Context

The flagged components are part of a mortgage calculator feature that:

  1. Takes user input (down payment, finance period)
  2. Performs calculations (may call backend APIs for complex formulas)
  3. Displays results
  4. Does NOT process payments, store credentials, or handle sensitive financial data

The tool appears to use keyword-based pattern matching to detect financial apps, which creates false positives for calculator utilities.

I think context-aware analysis could help here. The tool could search for actual indicators of financial apps that need root detection, like payment sdks (Stripe, Paypal, etc), banking apis, transaction processing code.

This way it could distinguish between apps with financial calculators vs apps that actually handle money/transactions.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions