Mobile apps are often treated as an extra channel alongside the “real” web application, which regularly translates into less attention to security. That’s not justified: a mobile app runs largely on a device you don’t control, communicates with the same backend as your web application, and in doing so introduces its own set of risks that a regular web application pentest doesn’t cover.
Why a mobile app needs to be tested differently
With a web application, the code runs on a server you control. With a mobile app, part of the logic literally runs on the user’s device, including any API keys, encryption implementations and local storage. An attacker with physical or root/jailbreak access to a device can decompile the app, intercept traffic and read local storage — things that simply aren’t possible with a purely server-side application.
For both iOS and Android, platform-specific points apply: on iOS, among others, the Keychain, App Transport Security and binary protections; on Android, among others, how permissions are enforced, how sensitive data is stored in SharedPreferences or local databases, and resistance to reverse engineering of the APK.
What a thorough mobile pentest investigates
- Local storage: are passwords, tokens or personal data stored unencrypted on the device?
- Communication with the backend: is certificate pinning implemented, and can traffic be intercepted with a proxy such as Burp Suite?
- Authentication and session management: do tokens remain valid after logout, and are they sufficiently short-lived?
- Reverse engineering resistance: how easy is the app to decompile, and are there hardcoded secrets in the code?
- Backend APIs: almost every mobile app talks to the same or similar APIs as the web application, and therefore deserves a full API pentest as part of the scope too.
A common assumption: “the App Store/Play Store already screens this”
Apple and Google mainly check apps for malware, policy compliance and basic functionality, not for application security in depth. An app that sails through the review process can still store sensitive data unencrypted, or have a backend that doesn’t properly enforce authorization. Store approval is not a security seal of approval.
When a mobile pentest delivers the most value
The greatest return comes from testing before a major release, particularly when new functionality is added around authentication, payments, or storing sensitive data. For apps that process a lot of personal or financial data, an annual test — just like with a regular web application pentest — is a reasonable baseline, supplemented with a retest after major changes.
A real-world example
During decompilation of an Android app that had sailed cleanly through Play Store review, the API key for a third-party service turned out to simply be sitting in the code as plain text — clearly readable after unpacking the APK with free, readily available tooling. That key granted access to a service well beyond the app’s intended scope. The app itself worked flawlessly, the store review flagged nothing unusual, and yet there was a direct route to abuse — exactly the kind of finding that only comes to light by actually decompiling the app, rather than just using it as intended.
How MonkeysICT tests mobile apps
We test both the app itself (static and dynamic analysis, on a real device) and the backend it talks to, so you know not just whether the app is secure, but whether the entire chain is. The report distinguishes between platform-specific findings (iOS versus Android) and findings that sit in the backend and therefore apply to both platforms.
