We test mobile applications from both client and server sides to discover OWASP Mobile Top 10 vulnerabilities, analyze insecure storage, encrypted communications, and authentication verification.
What's included
- Static analysis of the compiled iOS (IPA) and Android (APK/AAB) binaries: reverse engineering, hardcoded secrets and API keys, exported components, and weak obfuscation.
- Dynamic and runtime analysis on jailbroken and rooted devices using instrumentation such as Frida and Objection to bypass controls and inspect the app while it runs.
- Insecure data storage review across the iOS Keychain, Android Keystore, shared preferences, SQLite databases, logs, and cached files for exposure of credentials and personal data.
- Transport security testing: TLS configuration, certificate pinning strength and bypass, and interception of the app's traffic to its backend.
- Full assessment of the backend and API layer the app depends on, including authentication, authorization, and OWASP API Security Top 10 issues.
- Platform resilience testing: jailbreak and root detection, anti-tampering, debugger and hooking defenses, and screen-capture or overlay exposure.
Methodology & standards
1. Scoping and profiling: identify target platforms, minimum OS versions, app entitlements, and the backend services in scope, and provision test builds and accounts.
2. Static assessment aligned to the OWASP MASVS: decompile and inspect the binary, manifest, entitlements, stored data, and cryptographic use.
3. Dynamic and instrumented testing per the OWASP MASTG: run the app on rooted and jailbroken devices, hook runtime methods, bypass pinning and root detection, and intercept API traffic.
4. Backend and API exploitation: test the server side with the same rigor as a web assessment, chaining device and server findings into real attack paths.
5. Risk rating with CVSS v3.1, reporting, and a complimentary retest of the remediated build.
Deliverables
- Executive summary linking mobile risk to customer trust, brand, and SAMA obligations for digital banking channels.
- Per-platform technical report that separates iOS and Android findings, each with its CVSS score, evidence, and reproduction steps.
- Mapping of every finding to its OWASP MASVS verification level to show your target assurance posture.
- Prioritized remediation guidance for mobile developers covering secure storage, pinning, and platform hardening.
- Retest report on a fixed build, suitable as app-store, auditor, and regulator evidence.
- Attestation letter of scope, methodology, and result for regulatory and partner due diligence.
Regulatory controls it satisfies
Typical timeline
A single-platform mobile assessment typically takes one to two weeks; testing both iOS and Android against a shared backend usually runs two to four weeks, with a complimentary retest of the remediated build.
Common questions
Do you need the source code?
No. We perform full black-box and grey-box testing on the compiled binaries. Source access is optional and only deepens the static analysis and root-cause tracing.
Will testing affect our production backend or live users?
No. We use dedicated test accounts and a staging or isolated backend where possible, and any destructive testing is agreed in advance, so live users and data are never at risk.
From the same practice