info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomePenetration TestingiOS Application Penetration Testing

iOS Application Penetration Testing

Static, runtime and network testing of your iOS build on jailbroken and stock devices, aligned to the OWASP Mobile Application Security Verification Standard.

An iOS app is code you hand to your attacker. Everything shipped in the binary — keys, endpoints, logic, client-side checks — is readable and modifiable by anyone willing to run it on a device they control. Testing an iOS app means assuming exactly that.

We test against OWASP MASVS v2 using the MASTG techniques, on both jailbroken devices (for full runtime instrumentation) and stock devices (to confirm what a typical user's environment actually exposes).

What we test

  • Insecure data storage — Keychain accessibility classes, NSUserDefaults, Core Data and SQLite stores, plist files, cached responses, snapshot images of sensitive screens, pasteboard leakage, iCloud and iTunes backup exposure
  • Binary and static analysis — hardcoded API keys, secrets and certificates, debug symbols, disabled compiler protections (PIE, stack canaries, ARC), third-party SDK review
  • Transport security — App Transport Security exceptions, certificate validation, certificate pinning implementation and its bypassability
  • Runtime manipulation — jailbreak detection bypass, method swizzling and hooking with Frida and Objection, tampering with client-side authorization and feature flags
  • Authentication — LocalAuthentication and biometric bypass, session and token handling, logout and background behavior, credential storage
  • IPC and entry points — custom URL schemes, universal links, share and app extensions, keyboard extensions, pasteboard and deep-link parameter injection
  • WebView issues — JavaScript bridges, local file access, and injection through content loaded into WKWebView
  • Backend interaction — every API the app calls, tested for the authorization flaws the mobile client normally hides

What we need from you

An IPA (TestFlight or a direct build), test accounts at each permission level, and any jailbreak-detection details you want us to work around rather than around. Source code is optional; supplying it converts the engagement into a hybrid review with deeper coverage.

Who it is for

Consumer fintech and banking apps, healthcare and telehealth apps subject to HIPAA, apps handling payment data in PCI DSS scope, and any team facing an App Store security review, an enterprise customer questionnaire or an annual compliance test.

Frequently asked

Do you test on a real device or a simulator?
Real devices. Simulators do not reproduce Keychain behavior, jailbreak detection, biometric flows or network stack specifics, so findings from a simulator alone would not be trustworthy.
We use certificate pinning. Will that block the test?
No. Pinning is part of what gets tested — we assess the implementation and bypass it under controlled conditions, which is exactly what a motivated attacker does. We report how hard it was to defeat.
Does the API need separate testing?
The app's backend is tested as part of the engagement. If the same API also serves a web application or partners, a dedicated API test is usually worth scoping alongside it.

Book a scoping call with the testing team

Tell us what you are shipping — applications, APIs, mobile builds, compliance deadline — and we will come back with scope, timeline and a fixed quote.