Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BBVA Perú #417

Closed
6 of 16 tasks
ncr6 opened this issue Mar 8, 2024 · 1 comment
Closed
6 of 16 tasks

BBVA Perú #417

ncr6 opened this issue Mar 8, 2024 · 1 comment
Assignees
Labels
app report App report of a banking app Peru 🇵🇪

Comments

@ncr6
Copy link

ncr6 commented Mar 8, 2024

Is there an existing issue for this?

  • I have searched the existing issues

App name

BBVA Perú

Link to app

https://play.google.com/store/apps/details?id=com.bbva.nxt_peru

App version

24.20.11

Country of the app

Peru

Build Number

2024030300

Device list

Pixel 6 Pro

Profile app tested in

Owner profile

Google Play installed?

Installed

Where did you install this app from?

Google Play Store

Google Play services Network permission revoked?

  • Revoked
  • Not revoked
  • I did not have Google Play services installed

Native code debugging

  • Allowed
  • Blocked

Exploit protection compatibility mode

  • Enabled
  • Disabled

Stock OS compatibility

  • Works
  • Does not work
  • Not tested

NFC payments

  • Works
  • Works but requires another service
  • Does not work
  • N/A (Not supported by app)
  • Not tested

Description of the app's functionality

Peruvian branch of the well known spanish bank. App features: opening bank accounts, wire transfers, bill payments, and instant mobile payments via phone number or QR code (Plin), NFC payments.

Tested working:

  • Opening a bank account.
  • Sign in, facial and DNI validation.
  • Bank transfers (between BBVA accounts and other banks).
  • Plin (mobile payments).
  • Enabling/disabling cards.
  • Generating dynamic CVV.
  • Digital Token (for authorizing operations).
  • Biometric (fingerprint) login.
  • Push notifications.

Tested not working / broken, even with Exploit protection compatibility mode enabled:

  • NFC Payments (option is disabled in menu).

Screenshot_20240307-233854

Are there any extra notes you think users should know about?

Sadly, it seems that NFC Payments might require passing Play Integrity's MEETS_STRONG_INTEGRITY check (if I'm wrong or anyone else has updates on this please comment below).

NFC Payments were tested with another phone running LineageOS without success, using the Play Integrity Fix by @chiteroman Magisk Module with a valid fingerprint to pass the MEETS_DEVICE_INTEGRITY check, after that, Google Wallet allowed NFC payments, but the option in the BBVA app was still disabled.

ADB logcat of the app if necessary

No response

@ncr6 ncr6 added the app report App report of a banking app label Mar 8, 2024
@spring-onion spring-onion self-assigned this Mar 22, 2024
@spring-onion
Copy link
Collaborator

Make sure to point them to the attestation compatibility guide too.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
app report App report of a banking app Peru 🇵🇪
Development

No branches or pull requests

2 participants