Skip to main content
Home/Services/Mobile Penetration Testing
iOS & Android Security Assessment

Mobile Penetration Testing

Rigorous security testing for iOS and Android applications against OWASP MASVS - assessing binary security, local storage, runtime manipulation, and API backends.

OWASP MASVS OWASP Mobile Top 10 SOC 2 Type II ISO 27001 PIPEDA PCI-DSS
engagement log Mobile Penetration Testing testing
day 01 scope test APK/IPA builds and backend staging accounts delivered agreed
day 01 static binary decompilation & hardcoded secrets review complete complete
day 02 finding hardcoded backend API master key uncovered in binary critical
day 02 hook SSL certificate pinning bypassed using Frida runtime script bypassed
day 03 finding unencrypted user session tokens stored in local SQLite db high
day 04 triage mobile vulnerability findings reviewed and validated published
day 04 deliver findings delivered with code-level fix recommendations 201
after retest updated app builds retested and verified at no extra fee retested
retest included human countersigned report your auditor accepts
1-2 weekstypical duration $8,500fixed scope, from 8deliverables 8methodology stages
Scope

What This Engagement Covers

The Service

Mobile apps run in hostile client environments where attackers can decompile binaries, tamper with runtime memory, intercept encrypted communications, and exploit local device storage. Our mobile penetration tests evaluate your iOS and Android apps against the OWASP Mobile Application Security Verification Standard (MASVS). We combine reverse engineering, dynamic runtime instrumentation (Frida, Objection), and backend API testing to ensure your mobile apps resist attack on both device and server.

What We Test

We assess both client-side application code and backend communication: iOS IPA and Android APK/AAB binaries, local data storage (Keychain, KeyStore, SQLite, SharedPreferences), SSL certificate pinning and bypass feasibility, runtime memory protection, jailbreak/root detection, inter-process communication (IPC), deep links, third-party SDK security, and mobile API endpoints.

Targets

Components Evaluated in Scope

Our testers systematically inspect the following architectural layers and attack vectors during the assessment.

iOS (IPA) and Android (APK / AAB) binaries
OWASP MASVS controls (Storage, Crypto, Auth, Network, Platform, Code)
Local data storage security (SQLite, Keychain, KeyStore, SharedPrefs)
SSL / TLS certificate pinning implementation and bypass resilience
Runtime application self-protection (RASP) and root/jailbreak detection
Reverse engineering, decompilation, and code obfuscation analysis
Mobile backend API endpoint security and authentication flows
Inter-process communication (IPC), activities, intents, and broadcast receivers
Deep links, custom URL schemes, and intent filter validation
Third-party library vulnerabilities and exposed tracking SDKs
Method

How We Run It

We deploy your applications to jailbroken and rooted physical devices and emulators. Using static analysis, we evaluate code obfuscation, hardcoded credentials, and cryptographic implementations. Dynamically, we hook runtime functions using Frida to test security control bypasses, intercept API traffic, and identify vulnerabilities in the backend servers servicing the mobile client.

01

Binary Extraction & Static Analysis

Decompiling the binary using Ghidra and JADX to examine source code, strings, secrets, and permissions.

02

Local Data Storage Security Audit

Examining device storage for plaintext credentials, PII, caching, and insecure database files.

03

Transport Security & Pinning Testing

Intercepting network traffic and testing SSL pinning bypass via dynamic method hooking.

04

Runtime Analysis & Memory Tampering

Using Frida to modify application runtime behavior, bypass auth checks, and inspect memory.

05

Platform Interaction & IPC Review

Testing exported activities, broadcast receivers, content providers, and deep links for injection.

06

Backend Mobile API Testing

Attacking backend endpoints uncovered during mobile traffic interception for authorization flaws.

07

Anti-Tamper & Root Detection Audit

Evaluating effectiveness of jailbreak/root detection, debugger detection, and code signing controls.

08

Reporting & Engineering Guidance

Providing MASVS-mapped findings, reproduction scripts, and platform-specific remediation advice.

Deliverables

What You Receive

Findings land in your tracker as you go, not only in a PDF at the end. Free retesting is included in scope, not billed as a change order.

  • OWASP MASVS-mapped mobile security findings report
  • Decompiled code snippets and static analysis vulnerability proofs
  • Dynamic instrumentation (Frida) scripts and reproduction steps
  • Backend API vulnerability assessment documentation
  • Platform-specific (Swift/Kotlin) secure coding recommendations
  • Executive summary of mobile application risk posture
  • Free retest verification of updated builds within 48 hours
  • Formal Letter of Attestation for app store and enterprise partner compliance
Typical Results

What We Usually Find

The issues this engagement surfaces most often. Your environment will differ, but this reflects typical exposure patterns.

Sensitive Data Stored Unencrypted in SQLite or SharedPrefs Hardcoded API Keys, Passwords, or Cryptographic Secrets Trivially Bypassed SSL Pinning or Insecure TrustManager Weak or Non-Existent Jailbreak / Root Detection Controls Exported Android Components Allowing Unauthorized App Access Improper Deep Link Validation Permitting Account Takeover Excessive Permissions Requested in Application Manifest Lack of Binary Obfuscation and Anti-Tampering Protections
Fit

Who This Is For

Enterprises Distributing Consumer or B2B Apps via App Store / Google Play
Canadian FinTech and Mobile Banking Applications
Digital Health and Telemedicine Apps Storing PHI on Device
Organizations Subject to Strict Data Protection Safeguards
Companies Deploying Mobile Workforce Tools on BYOD Devices
Firms Preparing for Enterprise Client Security App Reviews
Standards this assessment supports

Findings are mapped directly to OWASP MASVS, OWASP Mobile Top 10, SOC 2 Type II, ISO 27001, PIPEDA, PCI-DSS, allowing your team to drop the report into an audit package without manual translation.

Canadian Operations

Calgary & Toronto Security Specialists

Mobile applications installed on Canadian user devices handle sensitive identity, financial, and location data protected under PIPEDA and provincial privacy laws. Ensuring device storage encryption and secure backend communication is essential for regulatory compliance and brand trust.

Calgary OfficeAlberta Operations
Toronto OfficeOntario Operations
FAQ

Common Questions

Do you test both iOS and Android platforms? +

Yes. We recommend testing both platforms concurrently. While they often share backend APIs, client-side vulnerabilities, cryptographic implementations, and platform security models differ significantly.

Do you require source code to test our mobile app? +

We can test using compiled binaries (IPA / APK) alone, simulating a real-world attacker. However, having access to source code allows for deeper grey-box verification of cryptographic algorithms and business logic.

Do we need to provide special builds with certificate pinning disabled? +

We prefer testing your production build to verify whether your certificate pinning can be bypassed by an adversary. If desired, you can also provide an unpinned build to accelerate backend API testing.

What devices do you use for mobile testing? +

We utilize physical dedicated test devices running recent versions of iOS and Android with customized research kernels, as well as specialized emulation environments.

Client Stories

Trusted by Fast-Growing Companies

JBWeb

Digital Agency

“From Pentest to malware analysis these guys know what they're doing.”

We came to Lorikeet Security with not so small task of tracking down the source of a cyber incident. Lorikeet Security looked at attack vectors and they set up a full test environment and really showed they knew what they were doing. With amazing analytics reports on down to the minute of login attempts. The level of detail that Cyber Insurance Companies wish they had in house - Those reports are an invaluable tool and give confidence and value add to the executive level for pre or post ransomware attacks.

SOCaaS Incident Response
Flowtriq

SaaS Platform

“Streamlined Security Testing with White Glove Service”

We used Lorikeet Security for a PTaaS pentest and briefly tried their ASM tool - both were amazing. Fast tests, accurate findings, and everything handled through a modern interface. The report summary, live chat, asset management, and live quoting features of the portal really stand out. Their 'white glove' touch contributed to a 10/10 experience. They're truly changing the pentest game with the new portal clients can use.

Penetration Testing Continuous Assessments
Next

Scope It in One Call

Tell us what is in scope and we come back with a fixed flat-rate price and a verified start date. No discovery-call maze, no hourly estimates that move.