Android and iOS, Tested Hard
Mobile Application Penetration Testing
We test your Android and iOS apps the way an attacker with the app in hand would. That means pulling the app apart, watching it run, and going after the API and the data it stores on the device.
See the engagement path, 6 phasesSee the full VAPT service index
Overview
A mobile application VAPT covers the app binary, its runtime behaviour and the backend it talks to. We look at how the app stores data, how it authenticates, how it protects itself from tampering, and how well the platform controls are used on both Android and iOS. The result is a clear view of what someone can extract, bypass or abuse once your app is on their phone.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Mobile Application engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Rules of Engagement. We agree the Android and iOS builds, test accounts and backend endpoints in scope, then set devices and testing windows. Activities: Confirm Android and iOS builds in scope; Provision test accounts and backend endpoints; Agree instrumented test devices; Set testing windows and contacts. Hands over Signed Rules of Engagement. Phase 2, Static Analysis. We decompile and inspect the app for hardcoded secrets, weak crypto, insecure storage and unsafe configuration on both platforms. Activities: Decompile the Android and iOS binaries; Hunt for hardcoded secrets and keys; Review local storage and crypto use; Check platform configuration flags. Hands over Static Analysis Findings. Phase 3, Dynamic Analysis. We run the app on instrumented devices, intercept its traffic and observe how it handles data, sessions and platform APIs at runtime. Activities: Run the app on instrumented devices; Intercept and inspect network traffic; Observe runtime data and session handling; Trace calls to platform APIs. Hands over Runtime Behaviour Findings. Phase 4, Manual Exploitation and Platform Checks. We attempt bypasses of root and jailbreak detection, certificate pinning, biometric and local auth, and abuse the app's own logic. Activities: Bypass root and jailbreak detection; Defeat certificate pinning with Frida; Attack biometric and local auth; Abuse the app's own business logic. Hands over Proven Client-Side Findings. Phase 5, Backend and Impact. We test the API behind the app and show how device-side and server-side flaws combine into real impact on accounts and data. Activities: Test the backend API the app calls; Chain device-side and server-side flaws; Map exposed accounts and data; Assess combined business impact. Hands over Impact and Risk Assessment. Phase 6, Reporting and Verified Retest. You get a report with proof of concept per platform and clear fixes, and we retest once you remediate to confirm closure. Activities: Write per-platform findings and fixes; Produce an executive summary; Walk your team through the results; Retest fixes and confirm closure. Hands over Final Report and Verified Retest. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Rules of Engagement
We agree the Android and iOS builds, test accounts and backend endpoints in scope, then set devices and testing windows.
What Happens In This Phase
- Confirm Android and iOS builds in scope
- Provision test accounts and backend endpoints
- Agree instrumented test devices
- Set testing windows and contacts
The Handover
Signed Rules of Engagement
The next phase starts from this.
Phase 01 Scoping and Rules of Engagement
We agree the Android and iOS builds, test accounts and backend endpoints in scope, then set devices and testing windows.
What Happens In This Phase
- Confirm Android and iOS builds in scope
- Provision test accounts and backend endpoints
- Agree instrumented test devices
- Set testing windows and contacts
The Handover
Signed Rules of Engagement
The next phase starts from this.
- 01
Scoping and Rules of Engagement
We agree the Android and iOS builds, test accounts and backend endpoints in scope, then set devices and testing windows.
OutputSigned Rules of EngagementActivities
- Confirm Android and iOS builds in scope
- Provision test accounts and backend endpoints
- Agree instrumented test devices
- Set testing windows and contacts
- 02
Static Analysis
We decompile and inspect the app for hardcoded secrets, weak crypto, insecure storage and unsafe configuration on both platforms.
OutputStatic Analysis FindingsActivities
- Decompile the Android and iOS binaries
- Hunt for hardcoded secrets and keys
- Review local storage and crypto use
- Check platform configuration flags
- 03
Dynamic Analysis
We run the app on instrumented devices, intercept its traffic and observe how it handles data, sessions and platform APIs at runtime.
OutputRuntime Behaviour FindingsActivities
- Run the app on instrumented devices
- Intercept and inspect network traffic
- Observe runtime data and session handling
- Trace calls to platform APIs
- 04
Manual Exploitation and Platform Checks
We attempt bypasses of root and jailbreak detection, certificate pinning, biometric and local auth, and abuse the app's own logic.
OutputProven Client-Side FindingsActivities
- Bypass root and jailbreak detection
- Defeat certificate pinning with Frida
- Attack biometric and local auth
- Abuse the app's own business logic
- 05
Backend and Impact
We test the API behind the app and show how device-side and server-side flaws combine into real impact on accounts and data.
OutputImpact and Risk AssessmentActivities
- Test the backend API the app calls
- Chain device-side and server-side flaws
- Map exposed accounts and data
- Assess combined business impact
- 06
Reporting and Verified Retest
You get a report with proof of concept per platform and clear fixes, and we retest once you remediate to confirm closure.
OutputFinal Report and Verified RetestActivities
- Write per-platform findings and fixes
- Produce an executive summary
- Walk your team through the results
- Retest fixes and confirm closure
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Mobile Application scope, running left to right in three stages. Stage one, what we run, 9 tools and techniques: MobSF, Frida, Objection, Burp Suite Professional, apktool, jadx, Ghidra, class-dump, Nuclei. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 6 published standards: OWASP MASVS, OWASP MASTG, OWASP Mobile Top 10, OWASP API Security Top 10, PTES, CVSS v4.0.
What We Run
9 tools
- apktool
- class-dump
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
6 standards
- OWASP
- OWASP
- OWASP
- OWASP
- PTES
Deliverables
What You Receive
- Findings report with proof of concept
- Per-platform results for Android and iOS
- Executive summary
- Remediation guidance
- Verified retest report
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Do you test both Android and iOS?
Yes. We test each platform separately because storage, permissions and platform controls differ, and we report findings per platform so your teams know exactly what to fix where.
Do you need the source code?
No. We can test from the compiled app alone. If you share source, we can go deeper and faster, but a black-box test on the binaries reflects what a real attacker starts with.
Can you get past certificate pinning and root detection?
Often, yes, and that is the point. We show you which protections hold and which we bypassed with Frida and Objection, so you know how much they really slow an attacker down.
Keep Moving Through VAPT
Service 2 of 7 in this practice area
Practice Area
More in VAPT
- Web ApplicationManual testing of your web apps against the OWASP WSTG
- APIREST, GraphQL and SOAP testing against the OWASP API Top 10
- Thick Client ApplicationDesktop app testing across binary, traffic and backend
- Network InfrastructureExternal and internal network testing with lateral movement
- IoT and EmbeddedDevice testing across firmware, hardware and radio
- CloudConfiguration and IAM testing across AWS, Azure and GCP