Mobile Application Security
Mobile App Penetration Testing. Your app. Under attack. By us.
iOS. Android. Hybrid. We analyze your mobile app against the OWASP Mobile Top 10, decompile the binary, instrument the runtime with Frida and uncover vulnerabilities that no automated scanner finds.
Organizations that trust AWARE7
- Pentests completed
- 500+
- both platforms
- iOS & Android
- fixed-price quote
- 24h
- fully covered
- OWASP Mobile Top 10
iOS & Android
Two platforms. Two security models. Equal thoroughness.
iOS and Android differ fundamentally in architecture, sandbox model and attack vectors. We know both in depth.
iOS-specific tests
Objective-C / Swift
- Jailbreak-based analysis - Bypass of jailbreak detection via Frida/Objection, sandbox integrity checks, dylib injection simulation on physical devices.
- Keychain dumping - Extraction of keychain entries on jailbroken devices, checking accessibility flags (kSecAttrAccessibleAlways), Secure Enclave binding.
- Binary analysis (otool, class-dump) - Disassembly of ARM64 binaries, reconstructing method signatures via class-dump, extracting hardcoded strings and keys.
- IPA reverse engineering - Unpacking and analyzing IPA archives, plist configurations, examining embedded frameworks and third-party SDKs.
- App Transport Security - Reviewing ATS exceptions in Info.plist, NSAllowsArbitraryLoads, domain-specific exceptions and minimum TLS version auditing.
- Certificate pinning bypass - SSL Kill Switch, Frida scripts and objection pinning disable for traffic interception even with pinning implemented.
Common with iOS: API communication analysis, local data storage, session management
Android-specific tests
Java / Kotlin / APK
- Root-based analysis - Magisk root, su binary checks, RootBeer detection bypasses via Frida simulation and validation of protection measures.
- APK decompilation (jadx) - JADX and Apktool for source code reconstruction, restoring Java/Kotlin classes, extracting resources and assets.
- Smali patching - Direct manipulation of Smali code to disable anti-tamper checks, bypass license checks or set debug flags.
- Intent / content provider abuse - Testing exported activities, services and broadcast receivers for unintended accessibility, intent injection and data exfiltration.
- Certificate pinning bypass - Frida scripts, TrustManager hooking and Magisk modules for interception of pinned traffic.
- WebView vulnerabilities - JavaScript interface injection, addJavascriptInterface, shouldOverrideUrlLoading, file access and universal XSS in embedded WebViews.
Common with Android: API communication analysis, local data storage, session management
We also fully test hybrid apps (React Native, Flutter, Xamarin). For React Native we analyze JavaScript bundles for hardcoded secrets and assess code obfuscation. Flutter apps are tested via Dart decompilation and native binary analysis. Xamarin apps receive a combined .NET and platform-native test. In all cases we conduct full OWASP MASVS-compliant testing.
OWASP Mobile Top 10:2024
All 10 categories. Fully tested.
The OWASP Mobile Top 10 is the international reference framework for mobile app security. Every finding in our report is mapped to one of these categories.
Improper Credential Usage
Hardcoded API keys, passwords and certificates in the binary and configuration files. We systematically extract all secrets from the app bundle - strings, embedded resources, configuration files and compiled code.
Inadequate Supply Chain Security
Vulnerable third-party libraries, insecure SDK integrations and compromised build pipelines. We inventory all dependencies and check them against known CVEs.
Insecure Authentication / Authorization
Weak authentication logic, missing biometric protection, client-side authorization checks and bypassable login flows. We test all auth mechanisms for circumventability via Frida and manipulated requests.
Insufficient Input / Output Validation
Missing validation of user inputs and API responses leads to injection attacks in SQLite databases, WebView XSS and content provider injections. Every input channel is tested for injection vectors.
Insecure Communication
Missing certificate pinning, insecure TLS configurations, mixed HTTP/HTTPS connections and excessive data sharing with third-party SDKs. We intercept all network traffic.
Inadequate Privacy Controls
Excessive permission requests, unjustified collection of sensitive data (location, contacts, microphone) and flawed GDPR privacy implementations. We audit the permission model and data flows.
Insufficient Binary Protections
Missing code obfuscation, disabled ASLR/PIE, missing stack canary, no tamper detection. We check all binary protections and test their actual effectiveness against Frida hooking.
Security Misconfiguration
Debug flags in production, excessive logging output, exported Android components without protection, flawed AndroidManifest configurations and insecure backup settings.
Insecure Data Storage
Auth tokens, personal data and payment information stored in cleartext in SharedPreferences, plist files, SQLite databases and app backups. We check all storage locations for encryption and access control.
Insufficient Cryptography
Outdated cryptographic algorithms (MD5, SHA-1, DES), self-implemented cryptography, insecure key management and predictable IV/nonce generation. We audit all cryptographic operations.
API & Backend
Mobile API security - the underestimated attack vector
Most critical vulnerabilities in mobile apps lie not in the app itself, but in the backend. We test both - and the interaction between app and server.
REST & GraphQL API testing
Full mapping of all API endpoints directly from app analysis. We test for missing authorization, BOLA/IDOR vulnerabilities and excessive data exposure.
Authentication token security
JWT vulnerabilities (alg:none, weak secrets), OAuth flows, session invalidation, token lifetime and refresh token security in the mobile context.
Rate limiting & business logic
Brute-force protection on login and payment endpoints, quantity manipulation, price manipulation and race conditions in time-sensitive API operations.
Server-side injection
SQL injection, NoSQL injection, SSRF and XXE via mobile API parameters - particularly relevant for APIs developed primarily for mobile clients.
API Endpoint Discovery - Example
Automatically mapped from app traffic, manually verified.
Methodology
3 phases. Systematic. Reproducible.
OWASP MASVS and OWASP MASTG-compliant methodology - transparently documented, every step traceable.
Static Analysis
Reverse engineering of the app binary or APK without execution. We reconstruct the source code, analyze configuration files, search for hardcoded secrets and audit embedded third-party libraries for known CVEs. Obfuscation is addressed through deobfuscation techniques.
Dynamic Analysis
The app is run on real jailbroken/rooted devices. We instrument the process with Frida at runtime, hook authentication functions, read memory regions and bypass anti-tamper mechanisms. SSL pinning bypasses enable full traffic interception.
Backend Testing
The app backend is tested both separately and in conjunction with the app. We map all API endpoints from app traffic, check authorization at endpoint and resource level, search for IDOR/BOLA vulnerabilities and test for injection attacks and business logic flaws.
Pricing & Packages
Transparent fixed prices
No hourly rate risk. No surprise costs. Binding fixed-price quote within 24 business hours after the free initial consultation.
Single Platform
iOS or Android
excl. VAT
- Full OWASP MASVS test
- Static & dynamic analysis
- API communication analysis
- CVSS-rated findings
- Management summary
- Retest of critical findings
Dual Platform
iOS + Android
excl. VAT
- Everything from Single Platform
- Both platforms fully tested
- Cross-platform comparative analysis
- Shared backend API review
- Prioritized overall roadmap
- Retest of all High/Critical findings
Enterprise
App + API + Backend
excl. VAT
- Everything from Dual Platform
- Full REST/GraphQL API test
- OWASP API Security Top 10
- Server-side vulnerability testing
- Combined app + API attack path
- Retest of all findings
Fixed-price commitment
No hourly rate risk. The agreed price is the final price.
Quote in 24 business hours
After the free initial consultation you receive a binding quote.
Retainer model available
Regular tests at fixed rates - ideal for continuous development.
All prices are indicative. The binding fixed-price quote is provided after the free initial consultation - within 24 business hours.
Compliance & Standards
Meet regulatory requirements with confidence
Mobile apps face growing regulatory pressure. Our pentest report is designed as evidence for audits, supervisory authorities and certifications.
App Store Security
Apple & Google Store Policies
Apple App Store Review Guidelines and Google Play Protect check for privacy and security violations. Our pentest proactively identifies store-relevant vulnerabilities before submission, reducing the risk of rejections or bans.
GDPR Art. 25
Privacy by Design
GDPR Article 25 requires data protection by design. Mobile apps process highly sensitive data - location, contacts, biometrics. Our report documents technical safeguards as evidence of appropriate technical measures for data protection audits and supervisory authorities.
ISO 27001
Vulnerability Management
ISO 27001:2022 Control A.8.8 requires active management of technical vulnerabilities. Our mobile app pentest provides structured, CVSS-rated findings that directly support vulnerability management and demonstrate compliance to certification auditors.
PSD2
Banking App Security
PSD2 requires strong customer authentication (SCA) and dynamic linking for financial apps. We test PSD2-relevant controls: biometric security, transaction binding, app integrity and anti-fraud mechanisms - following EBA guidelines on mobile security.
Why AWARE7 for your mobile app pentest
What sets us apart from other providers
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees - tailored to mid-sized companies, personal, without enterprise overhead.
Research and teaching as our foundation
20 %Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies analyse millions of websites and tens of thousands of phishing emails - published at ACM and Springer conferences. Three of our executives are professors at German universities at the same time.
Digital sovereignty - no compromises
100 %All data is stored and processed exclusively in Germany - without US cloud providers. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations. VS-NfD compliant on request.
Fixed price within 24h - predictable project timelines
24 hWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
Your dedicated contact
1:1A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security - without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house - and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA - we know the requirements and deliver evidence that auditors accept.
References
Client references
These case studies are available in German.
How it works
From consultation to report
Three steps. No hidden effort. No surprises.
Free initial consultation
In a 30-minute call we clarify your specific use case: platforms, app complexity, special requirements (e.g. compliance, CI/CD integration). You receive a binding fixed-price quote within 24 business hours.
Duration: 30 minutes
Test execution
After contract signing and kick-off our team starts immediately. You provide build artifacts and test accounts. We test in an isolated environment and report critical findings proactively - without waiting for the final report.
Duration: 5-18 business days per package
Report & retest
You receive the complete final report with management summary, technical findings and remediation roadmap. After fixing vulnerabilities we conduct the retest and issue a verification addendum - as evidence for auditors.
Including retest certificate
FAQ
Frequently asked questions about mobile app pentests
Which platforms are tested?
Do you need access to the app source code?
How long does a mobile app penetration test take?
Which tools do you use?
Is CI/CD integration possible?
Does the pentest help with app store compliance?
Is there a retest after vulnerabilities are fixed?
How is the report structured?
How do I prepare for the test?
How much does a mobile app penetration test cost?
Aus dem Blog
Weiterführende Artikel
Antivirensoftware auf dem Smartphone - Brauche ich sie wirklich?
Ist eine Antivirensoftware auf dem Smartphone wirklich nötig? Dieser Frage gehen wir nach und belegen Sie mit aktuellen Studien!
Firefox Focus für iOS vereint Browser, blockt Ads und Tracking!
Firefox Focus für iOS blockt nicht nur Werbung, sondern auch Analyse und soziale Tracker. So bleibt eure Privatsphäre erhalten und deine Daten deine!
Gibt es den Tor Browser für iOS?
Wer gerne anonym im Internet unterwegs ist oder das Darknet verwenden möchte, kommt am Tor Browser nicht vorbei. Aber gibt es den Tor Browser auch für iOS?
Ready for an honest look at your app security?
We analyze your iOS or Android app and deliver clear, reproducible findings. Fixed-price quote within 24 business hours after the initial consultation.
Kostenlos · 30 Minuten · Unverbindlich
Certifications & Standards