





Review SharedPreferences for sensitive values, ensuring anything confidential moves to the Keystore-backed path or is derived on demand. Validate backup exclusion flags and scoped storage usage. Test content provider boundaries and intent exposures. Explore autofill, keyboard suggestions, and clipboard handling for leaks. Examine WebView caches and download directories. A past bug involved session tokens lingering in a debug-only preference key that survived upgrades; documenting a small migration script diffused risk gracefully across the release train.
Confirm Keychain accessibility classes align with lock screen expectations and threat models. Check NSUserDefaults for accidental secrets, and ensure sensitive files use appropriate protection classes, considering background fetch tasks. Audit screenshot redaction on app switcher and notification previews for sensitive summaries. Investigate pasteboard interactions involving cross-app data. One team discovered analytics events occasionally included masked but reconstructable identifiers; tightening schemas and adding server-side scrubs preserved insight without compromising user dignity or regulatory posture.