mobile app can accept data from all kinds of sources. In the absence of sufficient encryption, attackers have the ability to modify inputs like cookies and environment variables.
When security decisions like authentication and authorization are made based on the values of these inputs, attackers can bypass the security of the software.