---
name: mobile-pentest
description: Use when pentesting an Android/iOS app — Frida 17 instrumentation, SSL-pinning & root/jailbreak bypass, Android 14/15 CA injection, exported-component/content-provider abuse, deep-link/WebView chains, biometric bypass, Flutter/React-Native RE
metadata:
  type: offensive
  phase: exploitation
  tools: frida, frida-tools, objection, jadx, apktool, reflutter, hermes-dec, hbctool, mitmproxy, burp, palera1n, dopamine, frida-ios-dump, bagbak, mobsf, drozer, nuclei
  mitre: TA0001
kill_chain:
  phase: [recon, exploit]
  step: [1, 4]
  attck_tactics: [TA0043, TA0001, TA0009, TA0006, TA0005]
  attck_techniques: [T1626, T1626.001, T1517, T1409, T1517, T1577, T1631, T1407, T1635, T1521, T1521.001, T1417, T1417.001, T1660, T1644, T1623]
depends_on: [recon-osint, reverse-engineering]
feeds_into: [exploit-development, web-pentest]
inputs: [apk_file, ipa_file, mobile_endpoint, app_package_id]
outputs: [finding_record, mobile_vulnerability_list, intercepted_traffic, extracted_secrets]
references:
  - references/environment-interception.md
  - references/android-component-attacks.md
  - references/webview-deeplink-exploitation.md
  - references/insecure-storage-crypto.md
  - references/ios-offensive.md
  - references/crossplatform-re-instrumentation.md
scripts:
  - scripts/universal_unpin.js
  - scripts/android_ca_inject.sh
  - scripts/manifest_attack_surface.py
  - scripts/component_fuzz.sh
  - scripts/ios_bypass_suite.js
  - scripts/hermes_triage.py
---

# Mobile Application Penetration Testing

## When to Activate

- Android/iOS application security assessment, bug-bounty mobile triage, or app-store reconnaissance
- Need to intercept TLS traffic (SSL/cert pinning, Android 14/15 Conscrypt-APEX trust store, Flutter/RN stacks)
- Bypass root/jailbreak or biometric-gating controls during dynamic analysis
- Enumerate and exploit exported components, content providers, deep links, and WebViews
- Extract secrets from insecure storage (SharedPrefs, SQLite, Keychain, Keystore) and reverse hybrid apps

## Technique Map

| Technique | ATT&CK | CWE | Reference | Script |
|-----------|--------|-----|-----------|--------|
| Lab build + Frida 17 server/gadget | T1635 | CWE-1188 | references/environment-interception.md | - |
| Android 14/15 Conscrypt-APEX CA injection | T1521.001 | CWE-295 | references/environment-interception.md | scripts/android_ca_inject.sh |
| SSL/cert-pinning bypass (Java TM/OkHttp/native) | T1521.001 | CWE-295 | references/environment-interception.md | scripts/universal_unpin.js |
| Root detection bypass (RootBeer/native stat) | T1633.001 | CWE-693 | references/environment-interception.md | scripts/universal_unpin.js |
| Exported activity/service/receiver abuse | T1626.001 | CWE-926 | references/android-component-attacks.md | scripts/manifest_attack_surface.py |
| Content-provider SQLi / path traversal (CVE-2025-48609) | T1409 | CWE-22, CWE-89 | references/android-component-attacks.md | scripts/component_fuzz.sh |
| Task hijacking / StrandHogg / TapTrap (USENIX '25) | T1517 | CWE-1021 | references/android-component-attacks.md | scripts/manifest_attack_surface.py |
| Deep-link / intent-redirect / scheme hijack | T1635, T1577 | CWE-939 | references/webview-deeplink-exploitation.md | scripts/component_fuzz.sh |
| WebView JS-interface RCE + file:// theft | T1577 | CWE-749 | references/webview-deeplink-exploitation.md | scripts/component_fuzz.sh |
| OAuth custom-scheme callback interception | T1635 | CWE-940 | references/webview-deeplink-exploitation.md | - |
| Insecure storage (SharedPrefs/SQLite/external) | T1409 | CWE-312 | references/insecure-storage-crypto.md | scripts/manifest_attack_surface.py |
| Keystore/Keychain misuse + dumping | T1634 | CWE-522 | references/insecure-storage-crypto.md | scripts/ios_bypass_suite.js |
| Biometric bypass (BiometricPrompt/LAContext) | T1634 | CWE-287 | references/insecure-storage-crypto.md | scripts/ios_bypass_suite.js |
| iOS jailbreak + JB-detection bypass | T1635 | CWE-693 | references/ios-offensive.md | scripts/ios_bypass_suite.js |
| IPA decrypt / class-dump / URL-scheme abuse | T1409, T1635 | CWE-200 | references/ios-offensive.md | scripts/ios_bypass_suite.js |
| Flutter RE / reFlutter pinning bypass | T1521.001 | CWE-295 | references/crossplatform-re-instrumentation.md | scripts/hermes_triage.py |
| React Native Hermes bytecode decompile | T1640 | CWE-656 | references/crossplatform-re-instrumentation.md | scripts/hermes_triage.py |

## Quick Start

```bash
# ---- ANDROID ----
# 0. Pull + statically triage the APK (manifest, secrets, exported surface, framework ID)
adb shell pm path com.target.app                              # locate split APKs
adb pull /data/app/.../base.apk .
python3 scripts/manifest_attack_surface.py base.apk -o surface.json
jadx -d src base.apk &  apktool d base.apk -o decoded

# 1. Frida 17: match server to host tools; push + run
frida --version                                              # e.g. 17.x  -> use matching server
adb push frida-server-17.x-android-arm64 /data/local/tmp/frida-server
adb shell "su -c 'chmod 755 /data/local/tmp/frida-server && /data/local/tmp/frida-server &'"

# 2. Trust Burp CA on Android 14/15 (APEX is immutable -> Zygote namespace bind-mount)
bash scripts/android_ca_inject.sh 9a5ba575.0 cacert.pem      # see reference for cert hashing

# 3. Spawn target with universal unpinning + root-detection bypass
frida -U -f com.target.app -l scripts/universal_unpin.js --no-pause

# 4. Hit the exported attack surface from surface.json
bash scripts/component_fuzz.sh com.target.app surface.json

# ---- iOS ----
frida-ios-dump -o app.ipa com.target.app                     # decrypt + pull (jailbroken)
frida -U -f com.target.app -l scripts/ios_bypass_suite.js --no-pause   # JB + pinning + biometric + keychain

# ---- HYBRID ----
file decoded/assets/index.android.bundle                     # "Hermes JavaScript bytecode" => RN
python3 scripts/hermes_triage.py base.apk                    # detect Flutter/RN, drive reFlutter/hermes-dec
```

## OPSEC & Detection (summary)

| Technique | Telemetry / IOC | Detection (Sigma / app-side) | OPSEC note |
|-----------|-----------------|------------------------------|------------|
| Frida instrumentation | `frida-server`/`gadget` ports (27042), `re.frida.server`, suspicious maps regions, named pipes `linjector` | App scans `/proc/self/maps` for `frida`, checks D-Bus port, thread `gum-js-loop`; Play Integrity | Use `frida-gadget` renamed lib, custom port `frida-server -l 0.0.0.0:1337`, magisk-hide / Shamiko |
| CA injection (APEX) | New trust anchor in process trust store; cert CN mismatch on pinned hosts | Network Security Config `<trust-anchors>` excludes user store; pinning catches it | Mount lives only in Zygote ns, vanishes on Zygote crash — re-inject; nothing written to /system |
| SSL-pinning bypass | TLS handshake to proxy IP; cert chain not app-pinned cert | App-side pin failure callbacks fire (if logged); telemetry SDK sees proxy cert | Hook before first request; for Flutter prefer reFlutter patch over runtime to avoid crash loops |
| Root/JB bypass | `getprop ro.debuggable`, su binaries, magisk paths queried | RootBeer/iXGuard SDK reports; SafetyNet/Play Integrity attestation server-side | Bypass client checks only; server-side attestation (Play Integrity / DeviceCheck) is unaffected |
| Exported component abuse | `am start`/`startservice`/`broadcast` from adb; foreign UID intent | App logs unexpected caller UID; `Binder.getCallingUid()` checks | Use on-device malicious app for realism; adb leaves shell history |
| Content-provider traversal | `content query` with `../`; openFile on out-of-dir path | FileProvider canonical-path check; CVE-2025-48609 patched Mar 2026 SPL | URL-encode `..%2f` to dodge naive filters; read-only first |
| TapTrap / task hijack | Transparent activity transition, taskAffinity overlap, animationScale abuse | TapTrap fixed Dec 2025 SPL; check `targetSdk`, taskAffinity="" | Zero-permission; works <Dec-2025 patch; user study: 100% missed at least one variant |
| Keychain/Keystore dump | `keychain_dumper`, frida memory scrape, SecItemCopyMatching hooks | Keychain items with `.biometryCurrentSet` resist hooking; SE-backed keys unextractable | JB device dumps keychain plaintext regardless of ACL; flag SE vs SW keys in report |
| Biometric bypass | LAContext `evaluatePolicy` / BiometricPrompt callback hook | Only works on boolean-result pattern, NOT `SecAccessControl`-gated crypto | Report root cause: auth result not bound to a crypto/keychain operation |

## Deep Dives

- **references/environment-interception.md** — Rooted/jailbroken lab, Genymotion/AVD, Magisk+Shamiko, Frida 17 breaking changes (bridge removal, frida-pm, frida-compile), gadget mode for non-root, Android 14/15 Conscrypt-APEX CA injection via Zygote namespace bind-mount, universal SSL-pinning bypass (Java TrustManager/OkHttp/Network Security Config/native BoringSSL), root-detection bypass.
- **references/android-component-attacks.md** — Manifest attack-surface enumeration, exported activity/service/broadcast/provider exploitation, content-provider SQLi & path traversal (CVE-2025-48609 MmsProvider), `intent://` redirection to non-exported components, task hijacking (StrandHogg 1.0/2.0 CVE-2020-0096) and TapTrap animation-driven tapjacking (USENIX Security '25), drozer + adb workflows.
- **references/webview-deeplink-exploitation.md** — `addJavascriptInterface` RCE, `setAllowUniversalAccessFromFileURLs`/`file://` local-file theft, deep-link → WebView open-redirect/XSS chains, `intent://` browsable-activity pivots, OAuth custom-scheme callback hijack (RFC 8252), iOS URL-scheme & Universal Link abuse, one-click browser-to-WebView exploitation.
- **references/insecure-storage-crypto.md** — Android SharedPreferences/SQLite/internal+external storage, Android Keystore misuse (non-hardware-backed keys, no `setUserAuthenticationRequired`), iOS Keychain ACLs & `keychain_dumper`, NSUserDefaults/plist leaks, biometric bypass (BiometricPrompt CryptoObject vs result-only, LAContext `evaluatePolicy`), hardcoded secrets & Firebase/S3 misconfig, MASVS-STORAGE mapping.
- **references/ios-offensive.md** — Jailbreak tooling matrix (palera1n checkm8 A8–A11/T2 iOS 15–18.x, Dopamine A8–A16 iOS 15–16.6.1, Dopamine HideJailbreak), JB-detection bypass (Frida stat/fopen/dlopen hooks + Shadow), IPA decryption (frida-ios-dump/bagbak), class-dump/Swift demangling, entitlements & URL-scheme analysis, Frida-version pinning gotchas.
- **references/crossplatform-re-instrumentation.md** — Flutter Dart-stack interception (reFlutter `libflutter.so` patch of `ssl_crypto_x509_session_verify_cert_chain`, iptables/proxydroid fallback), React Native Hermes bytecode RE (hermes-dec, hbctool patch/reassemble, hermes-decomp, `CatalystInstanceImpl.loadScriptFromAssets` Frida hook), native `.so` JNI/`JNI_OnLoad` analysis in Ghidra/IDA.
