When we think about cyber attacks, we usually think about someone targeting a backend system or an API gateway, but in my experience with securing mobile apps, It occurred to me that user's the device itself could also serve as an entry point.

A legitimate user might open your app on a normal device, while a potential attacker, might be using:

A rooted device

running an emulator at scale

A custom or modified Android ROM