Talking with people, it is frequently considered that having a mobile application without certificate pinning is a vulnerability. But I rarely see people mentioning it for web applications.
The question is, why is this issue only mentioned for mobile apps? Is there a higher risk derived out of this vulnerability on mobile apps?
Thinking about it, considering that the degree of difficulty is about the same for installing a rogue certificate on both pc and mobile, I would say that the vulnerability should exist in both cases, but in the case of web apps, there would be no remediation action since the hpkp which I think is the only way to achieve cert pinning is becoming obsolete.
Now none of the people I've talked with could give some reasonable explanations, so that's why I wanted to see if there is indeed any good justification for the mobile cert pinning.