Skip to main content

Changelog

[15.16] - 2026-09-03​

GENERAL​

Fixed​

  • None

Added​

  • MCSDK now handles app state changes automatically, triggering suspend and resume events when the app moves between the background and foreground. SDK-828

Changed​

  • (Android) Support Theametrix-SDK and prevent crashing during usage. KHC-7821, SDK-985
  • Update the list of third-party licenses provided by the RequestLicensesEvent. SDK-945
  • Optimised key share handling for TLS-1.3 connections. This should ensure that almost all servers are happy with the key shares offered by the client, thus avoiding an extra round trip where the server asks for a key for its desired key sharing algorithm. SDK-780
  • (Android) Fix the library loading on ARM64 MTE enabled devices. KHC-7689 ,SDK-990, SDK-900.
  • Updated SSL Library. SDK-658
  • Starting with MCSDK 15.16, SHA-1 will no longer be supported for TLS connections.SDK-658

DIGITANIUM​

Fixed​

  • None

Added​

  • Implement a safety mechanism for multi-assets in the SSMS case. SDK-937

Changed​

  • Starting with MCSDK 15.16 we no longer support cipher suites involving the CCM-8 mode for TLS connections. Note that "regular" CCM mode is not affected, it is only the CCM variant that shortens the integrity check value to only 8 bytes, that is no longer permitted. We don't expect this to have any impact in practice as using CCM-8 seems an unlikely server side configuration. SDK-658

KOBIL Shift Lite​

Fixed​

  • An issue where tms handling results in "cms signature invalid" when switching back and forth between SE and virtual smart card keys. KHC-7855, SDK-981
  • (iOS) Fixed an issue where the detection of the zombie sockets take a lot of time upon network change. SDK-1008

Added​

  • Introduce a new HTTP stack that ensures that only one TCP connection is used for multiple requests towards the same host in case of HTTP2. For HTTP1.1 the amount of TCP requests towards the same host is tried to keep at a minimum, however, in order to avoid long queuing time of single requests multiple TCP connections to the same host might be opened. In order to get the best performance it is recommended to use HTTP2. Additionally, the new stack decreased the overall process time on client side for each single HTTP request. SDK-788, SDK-791

Changed​

  • None

API Changes​

General​

  • (Android) We now require at least API level 24(Android 7), previously the minimum required was API level 21(Android 5). This is required by a third party library libuv which is an important part of our improved HTTP stack. SDK-986
  • Added KSMGetSdkStateEvent, KSMGetSdkStateResultEvent and KSMLoggedIn state under iOS, and GetSdkStateEvent, GetSdkStateResultEvent and SdkState.LOGGED_IN under Android. With this new events it is possible at any time to retrieve the current state of the SDK. SDK-867

Digitanium​

  • None

KOBIL Shift Lite​

  • None

DEPRECATION NOTES​

  • None

KNOWN ISSUES​

  • None

Used Component Versions​

  • MasterController Android Wrapper: 190.2
  • MasterController iOS Wrapper: 195.3
  • idpsdk Android: 4.4
  • idpsdk iOS: 4.4
  • H-Android: 32.1
  • H-Bridge iOS: 17.0
  • H-Bridge Android: 18.1
  • UI-hardening: 32.1
  • A-L: 14.1
  • TWV Proxy Android: 20.1

[15.15] - 2026-06-16​

GENERAL​

Fixed​

  • (Android) Fixed false positive JBreak[1](C000000) due to google attestation root key rotation. This was introduced with MC SDK 15.13. SDK-929
  • (Android) Fixed crashes on rare Android devices with android 29+. DS-9629, SDK-886
  • (Android) Fixed crashes on Samsung Galaxy S26, Samsung Galaxy S25 devices with March/May 2026 software update. DS-9616, DS-9508/KHC-7584, SDK-881

Added​

Changed​

  • (Android) Improved detection of the “Godfather” malware family by introducing two new risk indicators:
    • MaliciousApp[4](1040000)
    • MaliciousApp[4](2040000)
      These indicators are intended to detect malware-specific characteristics associated with Godfather. A detailed description of the new risk indicators is available in the Risk Bit documentation(v2.0). DS-9376, SDK-736

DIGITANIUM​

Fixed​

  • None

Added​

  • None

Changed​

  • None

KOBIL Shift Lite​

Fixed​

  • Fixed an issue that led to warning log lines in the Ast Login Service during login. SDK-895

Added​

  • None

Changed​

  • None

API Changes​

General​

  • (Android)Fix for parallel loading of webviews with and without cert-pinning. SA2-3130, SDK-935
    • No more singleton certificate validation, each webview instance now has an own validation instance
    • API CHANGE cp1 and cp2 (enable/disable certificate pinning), now need the webview as a parameter in addition to the certificates
      • PinningProxy.cp1(webView, certChain)
      • PinningProxy.cp2(webView,certChain)
    • API CHANGE cp15 (setting the connection timeout), now needs also the webview as a parameter in addition to the timeout
      • PinningProxy.cp15(webView, timeOut)
  • Added the optional flag useKobilTruststore to the KSMCreateHttpCommonRequestResultEvent under iOS and to the CreateHttpCommonRequestEvent under Android. If set to true the SDK will use the ssmsSSLBundle from the sdk_config.xml for the certificate pinning of the request and in the case the astServerBackend parameter in the mc_config.json is set to ssms. In case that the astServerBackend parameter in the mc_config.json is set to maverick, the tlsBundle of the sdk_config.jwt is used for the certificate pinning of the request. SDK-873, SDK-915
  • Added KSMGetUserListEvent, KSMGetUserListResultEvent and KsUserListEntry under iOS and GetUserListEvent, GetUserListResultEvent and UserListEntry under Android. With this new events it is possible at any time to retrieve all activated users, those that have been activated in the case the astServerBackend in the mc_config.json was set to ssms, and also those that have been activated in the case the astServerBackend in the mc_config.json was set to maverick. The flag isSsmsUser in the KsUserListEntry on iOS and the UserListEntry on Android help to distinguish between the two types of users. SDK-869

Digitanium​

  • None

KOBIL Shift Lite​

  • Added the astClientID as parameter to the KSOfflineLoginResultEvent and KSSetAuthorisationCodeResultEvent under iOS as also to the OfflineLoginResultEvent and SetAuthorisationCodeResultEvent under Android. SDK-868
  • It is possible now to delete all activated shift users by passing an empty user identifier and tenant id to the DeleteUserEvent under Android or the KSDeleteUserEvent under iOS. SDK-829

DEPRECATION NOTES​

  • None

KNOWN ISSUES​

  • None

Used Component Versions​

  • MasterController Android Wrapper: 187.1
  • MasterController iOS Wrapper: 193.2
  • idpsdk Android: 1.1
  • idpsdk iOS: 1.1
  • H-iOS: 29.4
  • H-Android: 30.4
  • H-Bridge iOS: 16.11
  • H-Bridge Android: 16.11
  • UI-hardening: 30.4
  • A-L: 11.4
  • TWV Proxy Android: 18.3
  • TWV iOS: 9.7
  • iOS-Hardening: 29.4