Reg. No. 40203410806 VAT LV40203410806

Theme

Book a consultation Book

2.05 Application security

Mobile App Security Testing

OWASP MASVS/MASTG-aligned testing of iOS and Android applications using static, dynamic and runtime analysis, together with testing of the supporting back-end API.

A mobile app is two attack surfaces in one: the binary running on a device you don’t control, and the backend API behind it. Attackers decompile the app, read hardcoded secrets, bypass certificate pinning and instrument the runtime to defeat client-side controls — then turn that understanding on the API. We test both halves as a single surface: static analysis of the binary, dynamic testing on jailbroken and rooted devices, and runtime manipulation with Frida and Objection to hook functions, bypass jailbreak/root detection and break SSL pinning.

Coverage is aligned with the OWASP Mobile Application Security Verification Standard (MASVS), with the MASTG used as a testing reference, producing a structured and repeatable report. We assess local storage, keychain and keystore use, cryptography, embedded secrets and API keys, transport security, platform use and resistance to tampering. Where included in scope, we also assess backend APIs for authorisation and authentication weaknesses such as BOLA, BFLA and authentication bypass. This can be combined with API Security Testing for end-to-end client and server coverage.

OWASP MASVS
verification standard, MASTG-tested
App + API
tested as one attack surface

01

How it works

  1. 01

    Scoping & threat model

    Define platforms, build types, data sensitivity and MASVS verification level; map the app and its backend.

  2. 02

    Static analysis

    Decompile and review the binary for secrets, weak crypto, insecure storage and platform misuse.

  3. 03

    Dynamic & runtime testing

    Frida/Objection instrumentation on jailbroken/rooted devices — pinning bypass, detection defeat, traffic interception.

  4. 04

    Backend API testing

    Pivot to the server and test BOLA/BFLA, authentication and business-logic abuse the app exposes.

  5. 05

    Reporting & retest

    MASVS-mapped, exploitability-ranked findings with remediation and re-test of fixes (optional).

02

Packages

Essential
Single-platform test (iOS or Android) against a MASVS verification level.
Comprehensive Popular
iOS and Android with runtime testing and backend API coverage.
Enterprise
Ongoing mobile security program across releases with developer enablement.

03

Frequently asked questions

Do you test the backend API as well as the app itself?

Yes. A mobile application and its back-end API form a connected attack surface. We assess the application package and runtime on the device, then test the API calls, authentication, authorisation and data flows used by the app. This provides client-to-server coverage rather than limiting the review to the binary.

What is OWASP MASVS, and why does it matter?

The OWASP Mobile Application Security Verification Standard (MASVS) defines recognised mobile-security control areas, while the MASTG provides corresponding testing guidance and test cases. Using them gives the assessment a structured and repeatable basis and makes it easier to explain the coverage to customers, partners and auditors.

Do you need our source code, or do you test the published app?

We can test either the published application or a build supplied by the client. Black-box testing assesses the distributed package from an external perspective. Source code, role-based test accounts and a non-production or debug build improve coverage and efficiency for grey-box or white-box testing, particularly for business logic and local data storage.

Can you bypass certificate pinning and jailbreak/root detection?

Where authorised and technically feasible, we use runtime-instrumentation tools such as Frida and Objection to assess certificate pinning, root or jailbreak detection and other client-side controls. The objective is to determine what data and functions remain exposed if those controls are bypassed, not merely to demonstrate a bypass.

How often should we test our mobile app?

At minimum annually, and before any major release. For apps that ship frequently or handle sensitive data — fintech, health, payments — we recommend testing each significant release and pairing it with our DevSecOps pipeline work so issues are caught continuously between full assessments.

04

Helpful tools

05

All services

Scope a test

[email protected] +371 2256 5353

Direct access to a senior specialist · Reply within 24 hours · NDA available on request