Offensive security

    Mobile Application Penetration Testing

    Assume the attacker owns the device.

    iOS and Android penetration testing across the app binary, local data storage, transport security and backend APIs.

    Test sequence

    Static: Binary, code and configuration analysis of the shipped app.

    Mobile Application Penetration Testing is a comprehensive security assessment for iOS, Android or cross-platform apps. It identifies weaknesses that could expose sensitive data, compromise user accounts or disrupt app functionality, then examines what a real-world attacker can do when they control the device. Testing follows OWASP MASVS and MASTG on rooted and jailbroken devices and covers local storage, transport, runtime controls and backend behaviour.

    • Tested to OWASP MASVS / MASTG on physical rooted and jailbroken devices.
    • iOS and Android can be scoped together or separately.
    • Findings separate device-side risk from server-side risk so fixes land in the right backlog.

    How this service connects

    Mobile testing is a specialised form of penetration testing built around an attacker-controlled device.

    If the backend serves other clients or has a broader interface, add dedicated API Penetration Testing beyond the endpoints exercised by the app.

    For connected customer portals and administrative interfaces, use Web Application Security Testing.

    Who should consider this assessment

    • iOS- or Android-only apps designed for specific user bases.
    • Cross-platform apps targeting a diverse audience.
    • Apps integrated with APIs for backend data exchange.
    • Data-heavy apps requiring advanced security measures.

    What you receive

    1. 01Platform-specific findings for iOS and Android, separated from shared backend issues.
    2. 02Reproducible evidence covering local storage, transport security, runtime controls and API authorisation.
    3. 03Prioritised remediation guidance and verification of agreed fixes.

    Service packages

    iOS Only Package

    Who it is for
    Mobile applications built exclusively for iOS.
    Scope
    Comprehensive security testing for authentication, data storage and communication.
    Ideal for
    Organisations focused solely on Apple users.

    €2,100 excl. VAT

    Configure with our team

    Android Only Package

    Who it is for
    Mobile applications built exclusively for Android.
    Scope
    Comprehensive security testing for authentication, data storage and communication.
    Ideal for
    Organisations targeting the Android user base.

    €2,100 excl. VAT

    Configure with our team

    iOS + Android Package

    Who it is for
    Mobile applications available on both platforms.
    Scope
    Comprehensive testing for iOS and Android, ensuring cross-platform consistency and security.
    Ideal for
    Businesses with apps targeting a diverse audience.

    €4,200 excl. VAT

    Configure with our team

    Expertise and delivery standards

    Certified offensive-security expertise

    Our experts hold certifications including OSEE, OSCP, OSWE, OSEP, OSED, OSWP, eWPTx, eMAPT, eCPPT, CRTO and CEH.

    ISO 9001 & ISO 27001

    Evolvice operates certified quality-management and information-security systems under ISO 9001:2015 and ISO 27001:2022.

    13+ years in IT delivery

    More than thirteen years of technology delivery inform scoping, communication, reporting and remediation support.

    Their penetration testing report was not only detailed but actionable. Our developers could immediately start fixing the issues.
    They helped us identify critical vulnerabilities we didn’t know existed. A truly professional and responsive team.
    From the initial scoping call to the final report, everything was handled with precision and professionalism.

    What the engagement covers

    01

    iOS testing

    Jailbroken-device testing: keychain usage, data protection classes, IPC and URL scheme handling.

    02

    Android testing

    Rooted-device testing: shared preferences, exported components, intents and WebView configuration.

    03

    Insecure data storage

    Credentials, tokens and personal data left recoverable on the device.

    04

    Transport security

    TLS configuration, certificate validation and pinning bypass resistance.

    05

    Runtime manipulation

    Frida and Objection-based hooking, root/jailbreak detection bypass, tamper resistance.

    06

    Backend API testing

    Server-side authorisation checks that must hold even when the client is fully compromised.

    Q&A

    Do you test iOS and Android separately?

    They can be scoped separately or together. Shared backend testing is performed once; platform-specific client testing is performed per platform.

    What do you need from us to start?

    The app build (IPA/APK or store access), test accounts for each user role, and any backend documentation. Source code is optional but improves depth.

    Does the backend need a separate test?

    The APIs the app uses are included. A broader API or infrastructure test is a separate scope — see API penetration testing.

    Is certificate pinning enough protection?

    No. Pinning raises the effort for an attacker but can be bypassed on a controlled device. Server-side authorisation must hold regardless of the client.

    Let us look at your current security position first.