Penetration Testing & AppSec

Mobile Application Penetration Testing

Comprehensive security testing for iOS and Android applications to protect user data and comply with SAMA requirements

We test mobile applications from both client and server sides to discover OWASP Mobile Top 10 vulnerabilities, analyze insecure storage, encrypted communications, and authentication verification.

What's included

  • Static analysis of the compiled iOS (IPA) and Android (APK/AAB) binaries: reverse engineering, hardcoded secrets and API keys, exported components, and weak obfuscation.
  • Dynamic and runtime analysis on jailbroken and rooted devices using instrumentation such as Frida and Objection to bypass controls and inspect the app while it runs.
  • Insecure data storage review across the iOS Keychain, Android Keystore, shared preferences, SQLite databases, logs, and cached files for exposure of credentials and personal data.
  • Transport security testing: TLS configuration, certificate pinning strength and bypass, and interception of the app's traffic to its backend.
  • Full assessment of the backend and API layer the app depends on, including authentication, authorization, and OWASP API Security Top 10 issues.
  • Platform resilience testing: jailbreak and root detection, anti-tampering, debugger and hooking defenses, and screen-capture or overlay exposure.

Methodology & standards

01

1. Scoping and profiling: identify target platforms, minimum OS versions, app entitlements, and the backend services in scope, and provision test builds and accounts.

02

2. Static assessment aligned to the OWASP MASVS: decompile and inspect the binary, manifest, entitlements, stored data, and cryptographic use.

03

3. Dynamic and instrumented testing per the OWASP MASTG: run the app on rooted and jailbroken devices, hook runtime methods, bypass pinning and root detection, and intercept API traffic.

04

4. Backend and API exploitation: test the server side with the same rigor as a web assessment, chaining device and server findings into real attack paths.

05

5. Risk rating with CVSS v3.1, reporting, and a complimentary retest of the remediated build.

Deliverables

  • Executive summary linking mobile risk to customer trust, brand, and SAMA obligations for digital banking channels.
  • Per-platform technical report that separates iOS and Android findings, each with its CVSS score, evidence, and reproduction steps.
  • Mapping of every finding to its OWASP MASVS verification level to show your target assurance posture.
  • Prioritized remediation guidance for mobile developers covering secure storage, pinning, and platform hardening.
  • Retest report on a fixed build, suitable as app-store, auditor, and regulator evidence.
  • Attestation letter of scope, methodology, and result for regulatory and partner due diligence.

Regulatory controls it satisfies

OWASP MASVS and MASTG
The engagement is verified against the Mobile Application Security Verification Standard and executed per the Mobile Application Security Testing Guide.
OWASP Mobile Top 10
Findings are classified against the current mobile risk taxonomy, including insecure data storage, weak cryptography, and insecure communication.
SAMA Cyber Security Framework
Supports secure delivery and testing of mobile banking and electronic-channel applications for member organizations.
NCA ECC-2:2024
Contributes to the application security and penetration testing controls for mobile services under the Cybersecurity Defence domain.
PDPL
Demonstrates protection of personal data stored on the device and transmitted to backend services.
ISO/IEC 27001
Supports the Annex A controls for secure development and technical vulnerability management of mobile assets.

Typical timeline

A single-platform mobile assessment typically takes one to two weeks; testing both iOS and Android against a shared backend usually runs two to four weeks, with a complimentary retest of the remediated build.

Common questions

Do you need the source code?

No. We perform full black-box and grey-box testing on the compiled binaries. Source access is optional and only deepens the static analysis and root-cause tracing.

Will testing affect our production backend or live users?

No. We use dedicated test accounts and a staging or isolated backend where possible, and any destructive testing is agreed in advance, so live users and data are never at risk.