Mobile apps put your code on devices you don't control. Anyone can download your app, decompile it, inspect what it stores, intercept its traffic and replay requests to your backend. A mobile application penetration test looks at the app the way an attacker with a rooted phone and a few free tools would — and, just as importantly, tests the APIs behind it.
What a mobile app pentest covers
A complete mobile assessment has two halves:
- The client — the iOS (.ipa) and Android (.apk/.aab) packages: how they store data, handle cryptography, authenticate users, talk to the network and interact with the operating system.
- The backend — the APIs the app calls. In most real incidents this is where the damage happens, because attackers simply call the API directly once they understand it. See our API testing guide.
OWASP MASVS and MASTG
The industry reference is the OWASP Mobile Application Security Verification Standard (MASVS), with testing procedures in the Mobile Application Security Testing Guide (MASTG). MASVS v2 groups requirements into control areas:
| Control group | What it covers | Example findings |
|---|---|---|
| MASVS-STORAGE | Secure storage of sensitive data | Tokens in plain-text preferences; sensitive data in logs or backups |
| MASVS-CRYPTO | Correct use of cryptography | Hard-coded keys; weak or custom algorithms |
| MASVS-AUTH | Authentication and authorization | Biometric checks that can be bypassed locally; client-side-only authorization |
| MASVS-NETWORK | Secure network communication | Missing certificate validation; cleartext traffic |
| MASVS-PLATFORM | Safe interaction with the OS and other apps | Exported Android components; unsafe WebViews; deep-link abuse |
| MASVS-CODE | Code quality and dependency hygiene | Outdated libraries; insecure input handling |
| MASVS-RESILIENCE | Resistance to reverse engineering and tampering | No root/jailbreak detection where required; easily patched logic |
| MASVS-PRIVACY | User privacy protections | Excessive permissions; unexpected data sharing with SDKs |
How testers approach a mobile app
- Static analysisDecompile the app, review manifests/plists, search for secrets, endpoints, keys and debug flags.
- Dynamic analysisRun the app on rooted/jailbroken test devices, inspect storage, hook functions at runtime, and test platform interactions.
- Traffic analysisIntercept and manipulate API calls, testing authentication, authorization and input handling on the backend.
- Business logicAbuse in-app purchases, rewards, OTP flows, KYC steps and other app-specific workflows.
- ReportingFindings mapped to MASVS with platform-specific remediation for iOS and Android developers.
Common high-impact mobile findings
- Secrets in the app binary — API keys, cloud credentials or third-party tokens that should live on the server.
- Backend trusts the client — prices, roles or feature flags sent from the app and accepted by the API.
- Weak session handling — long-lived tokens stored insecurely, no server-side revocation.
- OTP and login abuse — no rate limiting, OTP returned in responses, or verification done on the device.
- Insecure WebViews — JavaScript bridges exposing native functions to web content.
Do you need certificate pinning and root detection?
It depends on your risk. For banking, payments, health and high-value apps, pinning and anti-tampering controls raise the bar for attackers and are often expected by regulators. For most other apps, they are defence-in-depth — useful, but no substitute for a secure backend. A good tester will bypass these controls during testing anyway (they are designed to slow attackers, not stop skilled ones) and will tell you whether your backend is safe once they are bypassed.
Preparing for a mobile pentest
- Provide test builds for both platforms (debuggable builds speed up testing; release builds show real-world protections — ideally provide both)
- Test accounts for each role, plus test payment methods or sandbox modes
- A list of the APIs and third-party SDKs the app uses
- Any MDM or enterprise distribution requirements
Cost and duration
A typical iOS + Android assessment including backend API testing takes 6–15 tester-days. Testing only one platform, or excluding the API, reduces effort — but excluding the API is rarely a good idea. See our pricing guide for ranges.
Frequently asked questions
Do we need to test both iOS and Android?
Usually yes. The platforms store data, handle permissions and implement security features differently, and the codebases often diverge even when built from a shared framework.
Is the backend API included in a mobile pentest?
It should be. Attackers interact with your API directly once they understand the app, so excluding it leaves the most important attack surface untested.
Can apps built with Flutter or React Native be tested?
Yes. Cross-platform apps need some different tooling for reverse engineering, but the same MASVS controls and API testing apply.
Need a mobile assessment? Request a quote or see our mobile app testing service.