24/7 SOC monitoring & incident responsesales@bugfoe.com
BestPentestingby BugFoe
Mobile

Mobile Application Penetration Testing: iOS & Android

Your app runs on devices attackers control. Here's how testers assess the app — and the APIs behind it — against OWASP MASVS.

Updated October 20263 min readBy the BestPentesting Security Research Team

Mobile apps put your code on devices you don't control. Anyone can download your app, decompile it, inspect what it stores, intercept its traffic and replay requests to your backend. A mobile application penetration test looks at the app the way an attacker with a rooted phone and a few free tools would — and, just as importantly, tests the APIs behind it.

What a mobile app pentest covers

A complete mobile assessment has two halves:

  1. The client — the iOS (.ipa) and Android (.apk/.aab) packages: how they store data, handle cryptography, authenticate users, talk to the network and interact with the operating system.
  2. The backend — the APIs the app calls. In most real incidents this is where the damage happens, because attackers simply call the API directly once they understand it. See our API testing guide.

OWASP MASVS and MASTG

The industry reference is the OWASP Mobile Application Security Verification Standard (MASVS), with testing procedures in the Mobile Application Security Testing Guide (MASTG). MASVS v2 groups requirements into control areas:

Control groupWhat it coversExample findings
MASVS-STORAGESecure storage of sensitive dataTokens in plain-text preferences; sensitive data in logs or backups
MASVS-CRYPTOCorrect use of cryptographyHard-coded keys; weak or custom algorithms
MASVS-AUTHAuthentication and authorizationBiometric checks that can be bypassed locally; client-side-only authorization
MASVS-NETWORKSecure network communicationMissing certificate validation; cleartext traffic
MASVS-PLATFORMSafe interaction with the OS and other appsExported Android components; unsafe WebViews; deep-link abuse
MASVS-CODECode quality and dependency hygieneOutdated libraries; insecure input handling
MASVS-RESILIENCEResistance to reverse engineering and tamperingNo root/jailbreak detection where required; easily patched logic
MASVS-PRIVACYUser privacy protectionsExcessive permissions; unexpected data sharing with SDKs

How testers approach a mobile app

  1. Static analysisDecompile the app, review manifests/plists, search for secrets, endpoints, keys and debug flags.
  2. Dynamic analysisRun the app on rooted/jailbroken test devices, inspect storage, hook functions at runtime, and test platform interactions.
  3. Traffic analysisIntercept and manipulate API calls, testing authentication, authorization and input handling on the backend.
  4. Business logicAbuse in-app purchases, rewards, OTP flows, KYC steps and other app-specific workflows.
  5. ReportingFindings mapped to MASVS with platform-specific remediation for iOS and Android developers.

Common high-impact mobile findings

  • Secrets in the app binary — API keys, cloud credentials or third-party tokens that should live on the server.
  • Backend trusts the client — prices, roles or feature flags sent from the app and accepted by the API.
  • Weak session handling — long-lived tokens stored insecurely, no server-side revocation.
  • OTP and login abuse — no rate limiting, OTP returned in responses, or verification done on the device.
  • Insecure WebViews — JavaScript bridges exposing native functions to web content.

Do you need certificate pinning and root detection?

It depends on your risk. For banking, payments, health and high-value apps, pinning and anti-tampering controls raise the bar for attackers and are often expected by regulators. For most other apps, they are defence-in-depth — useful, but no substitute for a secure backend. A good tester will bypass these controls during testing anyway (they are designed to slow attackers, not stop skilled ones) and will tell you whether your backend is safe once they are bypassed.

Preparing for a mobile pentest

  • Provide test builds for both platforms (debuggable builds speed up testing; release builds show real-world protections — ideally provide both)
  • Test accounts for each role, plus test payment methods or sandbox modes
  • A list of the APIs and third-party SDKs the app uses
  • Any MDM or enterprise distribution requirements

Cost and duration

A typical iOS + Android assessment including backend API testing takes 6–15 tester-days. Testing only one platform, or excluding the API, reduces effort — but excluding the API is rarely a good idea. See our pricing guide for ranges.

Frequently asked questions

Do we need to test both iOS and Android?

Usually yes. The platforms store data, handle permissions and implement security features differently, and the codebases often diverge even when built from a shared framework.

Is the backend API included in a mobile pentest?

It should be. Attackers interact with your API directly once they understand the app, so excluding it leaves the most important attack surface untested.

Can apps built with Flutter or React Native be tested?

Yes. Cross-platform apps need some different tooling for reverse engineering, but the same MASVS controls and API testing apply.

Need a mobile assessment? Request a quote or see our mobile app testing service.

BestPentesting Security Research Team
Written and technically reviewed by practising penetration testers and SOC analysts. Last reviewed October 2026. See our methodology.

Ready to find your risks before attackers do?

Tell us what you need tested or monitored. A senior consultant replies within one business day with a scoped, fixed-price proposal.

  • Fixed-price proposal
  • Reply within 1 business day
  • NDA on request