MOBILE APPLICATIONS
Mobile application penetration testing
Your mobile app runs on a device you do not control, which means an attacker gets the binary, the local storage and the traffic. We test all three, plus the backend the app talks to.
Testing follows the OWASP MASVS verification standard and the MASTG testing guide, so coverage is measurable rather than a matter of who happened to test it.
THEY TRUST US
MOBILE APPLICATIONS
What we test on iOS and Android
A mobile engagement covers far more than the screens a user sees. We work from a real device and a real build, decompile and instrument where needed, and chase every path an attacker could take from a stolen phone or a rooted handset.
Where the app is only a thin client, the real risk usually lives in the API behind it — that is in scope too.
Coverage by MASVS category
| Area | What we look for |
|---|---|
| Data storage | Secrets in shared preferences, unencrypted databases, sensitive data on external storage, data surviving in backups. |
| Transport | Cleartext traffic, missing certificate validation, TLS pinning that can be bypassed at runtime. |
| Credentials and sessions | Hardcoded API keys, tokens written to logs, session tokens that replay, biometric prompts that gate nothing. |
| Binary protections | Debuggable release builds, absent root/jailbreak detection, repackaging and tampering resistance. |
| Platform interfaces | Exported components, deeplink abuse, WebView JavaScript bridges, content provider path traversal. |
| Supply chain | Trojanised SDKs, dependency confusion, unsigned dynamic code loading. |
Each row links to the matching chapter in the Haxoris Wiki, where we document the weakness, how it is exploited and how to fix it.
How a mobile engagement runs
Two to four weeks end to end for a typical app, including the retest.
Scoping
We agree the platforms, the build, the test accounts and whether the backend is in scope. You get a fixed price before anything starts.
Static analysis
We decompile the build, review the manifest and entitlements, and hunt for secrets, weak crypto and debug artefacts left in the release.
Dynamic testing
On a real device: runtime instrumentation, traffic interception, pinning bypass, storage inspection and abuse of exported interfaces.
Backend testing
The APIs the app depends on, tested with the same rigour as a web application — authorisation, IDOR, rate limits and business logic.
Report and retest
Findings with evidence and remediation, then a free retest once your fixes ship.
What you get
Every mobile engagement includes:
iOS and Android tested from a real device
Report mapped to MASVS categories
Reproduction steps your developers can follow
Free retest once fixes are deployed
Backend API testing included where in scope
Testing by OSCP- and eMAPT-certified testers
TESTIMONIALS
What our clients say about us
Mobile penetration testing — common questions
01 Do you need the source code?
No. We work black-box from the release build by default. If you can share source or a debug build we will use it — grey-box testing finds more in the same number of days — but it is not a requirement.
02 Do you test both iOS and Android?
Yes. Most clients test both, since the two platforms fail differently: Android tends to leak through exported components and storage, iOS through keychain misuse and jailbreak-detection bypass.
03 Is the backend API included?
It can be, and usually should be. A mobile app is often a thin client over an API where the real authorisation logic lives. We scope it explicitly so there is no ambiguity about what was covered.
04 How much does mobile penetration testing cost?
A single-platform app starts from around €2,000. Testing both platforms plus the backend typically runs 8 to 15 person-days. We quote a fixed price after a short scoping call.
05 Can you test an app that is not published yet?
Yes, and it is the better time to do it. Send us a signed build — TestFlight, an APK or an internal track — and we will test it before it reaches your users.
Get your mobile app tested
Tell us the platforms and roughly what the app does, and we will come back with a fixed price and a schedule. Application penetration testing
Book a free scoping call