About 10 years ago, I set up an automated system to test whether Android apps choose to bypass HTTPS security or not. Almost 24000 vulnerabilities later, I was... not impressed.
Just for lulz, I decided to test some iOS apps using a telephone and my fingers. Yes, the situation is much better than it was back then. No, I should not have been able to find over a dozen vulnerable apps by hand this easily.