APOLLOSEC

Mobile application penetration testing

Testing of your iOS and Android apps, and the back end they talk to, by people who take the app apart the way an attacker would.

Your app runs on someone els’s device

A mobile app runs on a device you do not control. Anyone can download it, decompile it, intercept its traffic and replay its requests. Anything shipped inside the app, from API keys to business rules, should be treated as public.

Most serious mobile findings are not in the app itself but in the API behind it, which often trusts the app to enforce rules it cannot enforce. We test both together.

What we test

  • Data on the device

    What is stored in files, databases, logs, caches and the keychain or keystore, and whether it survives logout.

  • Network traffic

    TLS configuration, certificate pinning, and what can be read or changed in transit.

  • Authentication and sessions

    Login, biometrics, token storage and refresh, and session expiry.

  • Back-end APIs

    Access control, data exposure and business logic in the services behind the app.

  • Code and binary

    Secrets in the build, debug features left enabled, obfuscation, and how easily root or jailbreak detection is bypassed.

  • Platform interaction

    Permissions, deep links, intents, exported components and WebViews.

How the engagement runs

  1. Builds and accounts

    You send test builds (an IPA and an APK, or TestFlight and internal track access) and accounts for each user role.

  2. Static analysis

    We decompile the app and review its configuration, libraries and code for secrets and weak points.

  3. Dynamic testing

    We run the app on test devices, intercept and modify its traffic, and test the API behind it.

  4. Report and retest

    Findings mapped to OWASP MASVS, the report within five working days, and a retest on your fixed build.

What you get

  • Findings mapped to OWASP MASVS controls, so you can see coverage as well as issues.
  • Separate actions for app developers and back-end developers.
  • Retest results against your next build.

When to commission it

  • Before a first public release, or a release that adds payments, health data or account recovery.
  • When an app store, partner or regulator asks for security testing.
  • After changing authentication, storage or networking libraries.
  • Yearly for apps that handle personal data, and more often if you release frequently.

Questions we get asked

Do you need our source code?

No, but it helps. We test the compiled app as an attacker would. With source code we can work faster and find issues that are hard to see from the outside.

Do you test both iOS and Android?

Yes. If both apps share a back end we scope them together, so the API is tested once.

Can you test an app with certificate pinning or root detection?

Yes. We bypass them on test devices as part of the test and report how much effort it took. They slow attackers down, but should never be the only control.

What is OWASP MASVS?

The OWASP Mobile Application Security Verification Standard. It sets out what a secure mobile app should do across storage, cryptography, authentication, network communication, platform interaction, code quality and resilience. We use it to structure testing and reporting.

Have your app tested before it ships.

Talk to us