Mobile application security

Mobile Apps Ship Your Code to Untrusted Devices.

Once installed, your application binary is in an attacker's hands. Nuclisafe combines static analysis of the package with dynamic runtime testing on real devices and emulators to find what an attacker with full device control could reach.

What we test

Testing coverage across the attack surface

Coverage is tailored to your application. The areas below are assessed where applicable to the agreed scope.

Insecure Data StorageCryptographySSL/TLS ValidationCertificate PinningExported ComponentsDeep LinksWebViewsAPI CommunicationRuntime ManipulationHardcoded SecretsInsecure ConfigurationsThird-Party DependenciesExcessive PermissionsAuthenticationSession Handling

Common weaknesses

Issues we frequently look for

Hardcoded Secrets

API keys, tokens and credentials recoverable from the binary or resource files.

Insecure Local Storage

Sensitive data written unprotected to preferences, databases, logs, caches or external storage.

Weak Transport Security

Missing certificate validation or bypassable pinning that allows traffic interception.

Exported Component Abuse

Activities, services, providers and deep links reachable by other apps on the device.

WebView Weaknesses

JavaScript bridges, file access and loading of untrusted content inside the app context.

Weak Runtime Protections

Trivially bypassed root/jailbreak, debugger and tamper checks enabling logic manipulation.

How we test

A manual-first testing approach

  • Static analysis: decompiling and reviewing binaries, hardcoded secrets, insecure configurations, dependencies and requested permissions.
  • Dynamic analysis: observing runtime behaviour, network communication, authentication flows and data handling on device.
  • Instrumentation and hooking to test client-side control bypass and runtime manipulation.
  • Backend API testing for the endpoints the app consumes, since mobile risk rarely stops at the client.
  • Findings mapped to MASVS controls with clear platform-specific remediation guidance.

Aligned frameworks

OWASP MASVSOWASP MASTGOWASP Mobile Top 10

Assessments are mapped to these industry frameworks and testing methodologies. This does not imply certification by, or partnership with, any of these organisations.

Example tools

MobSFFridaObjectionDrozerAPKToolJADXBurp Suite

Illustrative only — tooling is selected per engagement and is not a guarantee of full coverage. Manual testing remains central to every assessment.

Deliverables

What you receive

Executive Summary

Business-level view of risk posture, key themes and priorities for leadership and stakeholders.

Technical Report

Detailed findings with affected endpoints, reproduction steps, evidence and references.

Proof of Concept

Validated demonstration of exploitability within the authorized scope, so nothing is theoretical.

Risk Rating

Severity based on impact and likelihood, supporting prioritization and remediation planning.

Remediation Guidance

Specific, actionable fix recommendations written for the developers who will implement them.

Retest Report

Post-fix verification confirming which findings are closed and which need further work.

Ready to start scoping?

Every assessment is scoped according to application complexity, attack surface and testing requirements.