Mobile Penetration Testing
Rigorous security testing for iOS and Android applications against OWASP MASVS - assessing binary security, local storage, runtime manipulation, and API backends.
What This Engagement Covers
The Service
Mobile apps run in hostile client environments where attackers can decompile binaries, tamper with runtime memory, intercept encrypted communications, and exploit local device storage. Our mobile penetration tests evaluate your iOS and Android apps against the OWASP Mobile Application Security Verification Standard (MASVS). We combine reverse engineering, dynamic runtime instrumentation (Frida, Objection), and backend API testing to ensure your mobile apps resist attack on both device and server.
What We Test
We assess both client-side application code and backend communication: iOS IPA and Android APK/AAB binaries, local data storage (Keychain, KeyStore, SQLite, SharedPreferences), SSL certificate pinning and bypass feasibility, runtime memory protection, jailbreak/root detection, inter-process communication (IPC), deep links, third-party SDK security, and mobile API endpoints.
Components Evaluated in Scope
Our testers systematically inspect the following architectural layers and attack vectors during the assessment.
How We Run It
We deploy your applications to jailbroken and rooted physical devices and emulators. Using static analysis, we evaluate code obfuscation, hardcoded credentials, and cryptographic implementations. Dynamically, we hook runtime functions using Frida to test security control bypasses, intercept API traffic, and identify vulnerabilities in the backend servers servicing the mobile client.
Binary Extraction & Static Analysis
Decompiling the binary using Ghidra and JADX to examine source code, strings, secrets, and permissions.
Local Data Storage Security Audit
Examining device storage for plaintext credentials, PII, caching, and insecure database files.
Transport Security & Pinning Testing
Intercepting network traffic and testing SSL pinning bypass via dynamic method hooking.
Runtime Analysis & Memory Tampering
Using Frida to modify application runtime behavior, bypass auth checks, and inspect memory.
Platform Interaction & IPC Review
Testing exported activities, broadcast receivers, content providers, and deep links for injection.
Backend Mobile API Testing
Attacking backend endpoints uncovered during mobile traffic interception for authorization flaws.
Anti-Tamper & Root Detection Audit
Evaluating effectiveness of jailbreak/root detection, debugger detection, and code signing controls.
Reporting & Engineering Guidance
Providing MASVS-mapped findings, reproduction scripts, and platform-specific remediation advice.
What You Receive
Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.
- OWASP MASVS-mapped mobile security findings report
- Decompiled code snippets and static analysis vulnerability proofs
- Dynamic instrumentation (Frida) scripts and reproduction steps
- Backend API vulnerability assessment documentation
- Platform-specific (Swift/Kotlin) secure coding recommendations
- Executive summary of mobile application risk posture
- Free retest verification of updated builds within 48 hours
- Formal Letter of Attestation for app store and enterprise partner compliance
What We Usually Find
The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.
Who This Is For
Findings are mapped directly to OWASP MASVS, OWASP Mobile Top 10, SOC 2 Type II, ISO 27001, PIPEDA, PCI-DSS, allowing your team to drop the report into an audit package without manual translation.
Calgary & Toronto Security Specialists
Mobile applications installed on Canadian user devices handle sensitive identity, financial, and location data protected under PIPEDA and provincial privacy laws. Ensuring device storage encryption and secure backend communication is essential for regulatory compliance and brand trust.
Common Questions
Yes. We recommend testing both platforms concurrently. While they often share backend APIs, client-side vulnerabilities, cryptographic implementations, and platform security models differ significantly.
We can test using compiled binaries (IPA / APK) alone, simulating a real-world attacker. However, having access to source code allows for deeper grey-box verification of cryptographic algorithms and business logic.
We prefer testing your production build to verify whether your certificate pinning can be bypassed by an adversary. If desired, you can also provide an unpinned build to accelerate backend API testing.
We utilize physical dedicated test devices running recent versions of iOS and Android with customized research kernels, as well as specialized emulation environments.
Trusted by Fast-Growing Companies
We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.
We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.
Scope It in One Call
Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.