Mashups on traditional desktop devices are a well-known source of security risks. In this paper, we examine how these risks translate to mobile mashups and identify new risks caused by mobile-specific characteristics such as access to device features or offline operation. We describe the design of SCCM, a platform independent approach to handle the various mobile mashup security risks in a consistent and systematic manner. Evaluating an SCCM implementation for Android, we find that SCCM successfully protects against common attacks such as inserting a malicious widget from the outside. Categories and Subject Descriptors D.2.m [Software Engineering]: Miscellaneous – reusable software. D.4.6 [Operating Systems]: Security and Protection – access controls. H.3.3 [Information Storage and Retrieval]:Information Search and Retrieval – Information filtering. H.3.5 [Information Storage and Retrieval]: Online Information Services – web-based services. General Terms Design, Security. Keyw...