Service

Mobile Penetration Testing

iOS and Android, binary to backend.

Static, dynamic and backend testing of native and hybrid apps against OWASP MASVS — including jailbreak and root, platform IPC, and certificate pinning.

What it is

Mobile apps fail where web apps do not: secrets baked into the binary, broken pinning, sensitive data in shared storage, IPC open to every other app on the device, and a backend that trusts the client far too much.

Testing covers the binary, the runtime, the platform surface and the APIs the app calls — on jailbroken or rooted devices and on stock devices where the difference matters. Built on OWASP MASVS v2 and the MASTG.

Method

  • Static analysis of the binary: hardcoded secrets, obfuscation, anti-tamper
  • Local storage: Keychain, Keystore, shared preferences, SQLite, file system
  • Platform IPC: intents, custom URL schemes, app extensions, deep links
  • Authentication, session and biometric integration testing
  • Certificate pinning and bypass attempts on a jailbroken or rooted device
  • Runtime instrumentation with Frida and objection
  • Backend API testing alongside the mobile flows
  • Push notification and OAuth flow inspection

What you get

  • Findings with binary and runtime evidence, plus backend reproduction
  • Each finding mapped to its MASVS v2 control group
  • Threat-model snapshot of trust boundaries on-device and to the backend
  • Fixes covering app code, infrastructure and platform configuration
  • Retest including a re-instrumented binary check

Ready to scope this engagement?

One email is enough to start. Tell us roughly what you want tested and we'll come back with a scoping call slot inside one business day.