Mobile Penetration Testing
iOS and Android, binary to backend.
Static, dynamic and backend testing of native and hybrid apps against OWASP MASVS — including jailbreak and root, platform IPC, and certificate pinning.
What it is
Mobile apps fail where web apps do not: secrets baked into the binary, broken pinning, sensitive data in shared storage, IPC open to every other app on the device, and a backend that trusts the client far too much.
Testing covers the binary, the runtime, the platform surface and the APIs the app calls — on jailbroken or rooted devices and on stock devices where the difference matters. Built on OWASP MASVS v2 and the MASTG.
Method
- Static analysis of the binary: hardcoded secrets, obfuscation, anti-tamper
- Local storage: Keychain, Keystore, shared preferences, SQLite, file system
- Platform IPC: intents, custom URL schemes, app extensions, deep links
- Authentication, session and biometric integration testing
- Certificate pinning and bypass attempts on a jailbroken or rooted device
- Runtime instrumentation with Frida and objection
- Backend API testing alongside the mobile flows
- Push notification and OAuth flow inspection
What you get
- Findings with binary and runtime evidence, plus backend reproduction
- Each finding mapped to its MASVS v2 control group
- Threat-model snapshot of trust boundaries on-device and to the backend
- Fixes covering app code, infrastructure and platform configuration
- Retest including a re-instrumented binary check
Related services
Web Application Penetration Testing
Web, REST, GraphQL and SOAP. Manual-first, exploit-validated, fix-prioritised.
View service →Vulnerability Assessment
Breadth-first sweep, manual triage, prioritised by exploitability.
View service →Cloud Penetration Testing
AWS, Azure, GCP. Assumed breach, IAM blast radius, real attacker paths.
View service →Ready to scope this engagement?
One email is enough to start. Tell us roughly what you want tested and we'll come back with a scoping call slot inside one business day.