Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of VAPT7 services in this practice area

Android and iOS, Tested Hard

Mobile Application Penetration Testing

We test your Android and iOS apps the way an attacker with the app in hand would. That means pulling the app apart, watching it run, and going after the API and the data it stores on the device.

See the engagement path, 6 phasesSee the full VAPT service index

Overview

A mobile application VAPT covers the app binary, its runtime behaviour and the backend it talks to. We look at how the app stores data, how it authenticates, how it protects itself from tampering, and how well the platform controls are used on both Android and iOS. The result is a clear view of what someone can extract, bypass or abuse once your app is on their phone.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Mobile Application engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Rules of Engagement. We agree the Android and iOS builds, test accounts and backend endpoints in scope, then set devices and testing windows. Activities: Confirm Android and iOS builds in scope; Provision test accounts and backend endpoints; Agree instrumented test devices; Set testing windows and contacts. Hands over Signed Rules of Engagement. Phase 2, Static Analysis. We decompile and inspect the app for hardcoded secrets, weak crypto, insecure storage and unsafe configuration on both platforms. Activities: Decompile the Android and iOS binaries; Hunt for hardcoded secrets and keys; Review local storage and crypto use; Check platform configuration flags. Hands over Static Analysis Findings. Phase 3, Dynamic Analysis. We run the app on instrumented devices, intercept its traffic and observe how it handles data, sessions and platform APIs at runtime. Activities: Run the app on instrumented devices; Intercept and inspect network traffic; Observe runtime data and session handling; Trace calls to platform APIs. Hands over Runtime Behaviour Findings. Phase 4, Manual Exploitation and Platform Checks. We attempt bypasses of root and jailbreak detection, certificate pinning, biometric and local auth, and abuse the app's own logic. Activities: Bypass root and jailbreak detection; Defeat certificate pinning with Frida; Attack biometric and local auth; Abuse the app's own business logic. Hands over Proven Client-Side Findings. Phase 5, Backend and Impact. We test the API behind the app and show how device-side and server-side flaws combine into real impact on accounts and data. Activities: Test the backend API the app calls; Chain device-side and server-side flaws; Map exposed accounts and data; Assess combined business impact. Hands over Impact and Risk Assessment. Phase 6, Reporting and Verified Retest. You get a report with proof of concept per platform and clear fixes, and we retest once you remediate to confirm closure. Activities: Write per-platform findings and fixes; Produce an executive summary; Walk your team through the results; Retest fixes and confirm closure. Hands over Final Report and Verified Retest. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Rules of Engagement

We agree the Android and iOS builds, test accounts and backend endpoints in scope, then set devices and testing windows.

What Happens In This Phase

  • Confirm Android and iOS builds in scope
  • Provision test accounts and backend endpoints
  • Agree instrumented test devices
  • Set testing windows and contacts

The Handover

Signed Rules of Engagement

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Rules of Engagement

    We agree the Android and iOS builds, test accounts and backend endpoints in scope, then set devices and testing windows.

    OutputSigned Rules of Engagement

    Activities

    • Confirm Android and iOS builds in scope
    • Provision test accounts and backend endpoints
    • Agree instrumented test devices
    • Set testing windows and contacts
  2. 02

    Static Analysis

    We decompile and inspect the app for hardcoded secrets, weak crypto, insecure storage and unsafe configuration on both platforms.

    OutputStatic Analysis Findings

    Activities

    • Decompile the Android and iOS binaries
    • Hunt for hardcoded secrets and keys
    • Review local storage and crypto use
    • Check platform configuration flags
  3. 03

    Dynamic Analysis

    We run the app on instrumented devices, intercept its traffic and observe how it handles data, sessions and platform APIs at runtime.

    OutputRuntime Behaviour Findings

    Activities

    • Run the app on instrumented devices
    • Intercept and inspect network traffic
    • Observe runtime data and session handling
    • Trace calls to platform APIs
  4. 04

    Manual Exploitation and Platform Checks

    We attempt bypasses of root and jailbreak detection, certificate pinning, biometric and local auth, and abuse the app's own logic.

    OutputProven Client-Side Findings

    Activities

    • Bypass root and jailbreak detection
    • Defeat certificate pinning with Frida
    • Attack biometric and local auth
    • Abuse the app's own business logic
  5. 05

    Backend and Impact

    We test the API behind the app and show how device-side and server-side flaws combine into real impact on accounts and data.

    OutputImpact and Risk Assessment

    Activities

    • Test the backend API the app calls
    • Chain device-side and server-side flaws
    • Map exposed accounts and data
    • Assess combined business impact
  6. 06

    Reporting and Verified Retest

    You get a report with proof of concept per platform and clear fixes, and we retest once you remediate to confirm closure.

    OutputFinal Report and Verified Retest

    Activities

    • Write per-platform findings and fixes
    • Produce an executive summary
    • Walk your team through the results
    • Retest fixes and confirm closure

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Mobile Application scope, running left to right in three stages. Stage one, what we run, 9 tools and techniques: MobSF, Frida, Objection, Burp Suite Professional, apktool, jadx, Ghidra, class-dump, Nuclei. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: OWASP MASVS, OWASP MASTG, OWASP Mobile Top 10, OWASP API Security Top 10, PTES, CVSS v4.0.

What We Run

9 tools

  • MobSF
  • Frida
  • Objection
  • Burp Suite Professional
  • apktool
  • jadx
  • Ghidra
  • class-dump
  • Nuclei

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

6 standards

  • OWASPMASVS
  • OWASPMASTG
  • OWASPMobile Top 10
  • OWASPAPI Top 10
  • PTES
  • CVSS v4.0
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Findings report with proof of concept
  • Per-platform results for Android and iOS
  • Executive summary
  • Remediation guidance
  • Verified retest report

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Do you test both Android and iOS?

Yes. We test each platform separately because storage, permissions and platform controls differ, and we report findings per platform so your teams know exactly what to fix where.

Do you need the source code?

No. We can test from the compiled app alone. If you share source, we can go deeper and faster, but a black-box test on the binaries reflects what a real attacker starts with.

Can you get past certificate pinning and root detection?

Often, yes, and that is the point. We show you which protections hold and which we bypassed with Frida and Objection, so you know how much they really slow an attacker down.

Keep Moving Through VAPT

Service 2 of 7 in this practice area