despite the user explicitly denying such request. 5.4.17 Mobile applications across available platforms such as Android and iOS, as stated in the CLS application, shall be subjected to the binary analysis. 5.4.18 The findings shall be resolved or justified as appropriately. Search for Vulnerabilities in the Public Domain 5.4.19 The testing laboratory shall examine sources of information publicly available to identify potential vulnerabilities in the DUT. 5.4.20 The testing laboratory shall also examine sources of information publicly available to identify generic vulnerabilities (vulnerabilities discovered on similar device-type) that could potentially be applicable for the DUT and determine if they are applicable for the DUT. 5.4.21 The testing laboratory can make use of several established sources. Examples are Common Vulnerabilities and Exposures (CVE), and public search engines (e.g. Google). 5.4.22 The testing laboratory shall also examine sources of information publicly available to check for DUT source code, unencrypted binary code, developer-confidential data, DUT user credentials, or other information that may be available to a potential attacker. E.g. source code or DUT default administrator credentials hosted on GitHub that are publicly accessible. 5.4.23 At this stage, the testing laboratory is not expected to conduct tests to verify if the identified vulnerabilities are exploitable. 5.5 PASS CRITERIA 5.5.1 The firmware and the companion mobile application shall be free from identified exploitable vulnerabilities using the binary analysers. For nonconformance, the developer and the testing laboratory can choose to provide due justification to CCC which must be supported by the testing laboratory. The exception will be reviewed and accepted by CCC on a case-by-case basis. 5.6 TESTING LABORATORY DELIVERABLES 5.6.1 The testing laboratory shall submit a report containing the following: 1. Verdict on the software errors 2. Verdict on the third-party library and hard-coded sensitive security parameters 3. Verdict on the mobile application scan (if applicable) 4. Results on the search for potential vulnerabilities in the public domain CLS Publication #2 | Page 13 of 49

Select target paragraph3