android-checklist.md (9106B)
1 --- 2 title: "Android APK Checklist" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/android-checklist.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-checklist.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Android APK Checklist 14 15 This checklist complements the OWASP Mobile Application Security Testing Guide; apply each item according to the application's threat model and authorized test scope.<sup>[[5]](#references)</sup> 16 17 ### [Learn Android fundamentals](android-app-pentesting/index.html#2-android-application-fundamentals) 18 19 - [ ] [Basics](android-app-pentesting/index.html#fundamentals-review) 20 - [ ] [Dalvik & Smali](android-app-pentesting/index.html#dalvik--smali) 21 - [ ] [Entry points](android-app-pentesting/index.html#application-entry-points) 22 - [ ] [Activities](android-app-pentesting/index.html#launcher-activity) 23 - [ ] [URL Schemes](android-app-pentesting/index.html#url-schemes) 24 - [ ] [Content Providers](android-app-pentesting/index.html#services) 25 - [ ] [Services](android-app-pentesting/index.html#services-1) 26 - [ ] [Broadcast Receivers](android-app-pentesting/index.html#broadcast-receivers) 27 - [ ] [Intents](android-app-pentesting/index.html#intents) 28 - [ ] [Intent Filter](android-app-pentesting/index.html#intent-filter) 29 - [ ] [Other components](android-app-pentesting/index.html#other-app-components) 30 - [ ] [How to use ADB](android-app-pentesting/index.html#adb-android-debug-bridge) 31 - [ ] [How to modify Smali](android-app-pentesting/index.html#smali) 32 33 ### [Static Analysis](android-app-pentesting/index.html#static-analysis) 34 35 - [ ] Check for [obfuscation](/hacktricks/mobile-pentesting/android-checklist#some-obfuscation-deobfuscation-information), root/emulator detection, and anti-tampering checks. [Read this for more information](android-app-pentesting/index.html#other-checks). 36 - [ ] Sensitive applications (like bank apps) should check if the mobile is rooted and should actuate in consequence. 37 - [ ] Search for [interesting strings](android-app-pentesting/index.html#looking-for-interesting-info) (passwords, URLs, API, encryption, backdoors, tokens, Bluetooth uuids...). 38 - [ ] Special attention to [firebase ](android-app-pentesting/index.html#firebase)APIs. 39 - [ ] [Read the manifest:](android-app-pentesting/index.html#basic-understanding-of-the-application-manifest-xml) 40 - [ ] Check if the application is in debug mode and try to "exploit" it 41 - [ ] Check if the APK allows backups 42 - [ ] Exported Activities 43 - [ ] Unity Runtime: exported UnityPlayerActivity/UnityPlayerGameActivity with a `unity` CLI extras bridge. Test `-xrsdk-pre-init-library <abs-path>` for pre-init `dlopen()` RCE. See [Intent Injection → Unity Runtime](/hacktricks/mobile-pentesting/android-app-pentesting/intent-injection).<sup>[[1]](#references)</sup> 44 - [ ] Content Providers 45 - [ ] Exposed services 46 - [ ] Broadcast Receivers 47 - [ ] URL Schemes 48 - [ ] Is the application [saving data insecurely, internally or externally](android-app-pentesting/index.html#insecure-data-storage)? 49 - [ ] Is any [password hard-coded or saved on disk](android-app-pentesting/index.html#poorkeymanagementprocesses)? Is the app [using insecure cryptographic algorithms](android-app-pentesting/index.html#useofinsecureandordeprecatedalgorithms)? 50 - [ ] Are all native libraries compiled as PIE where the platform requires it? 51 - [ ] Use [static Android analyzers](android-app-pentesting/index.html#automatic-analysis) to complement manual review. 52 - [ ] `android:exported` **mandatory on Android 12+** – misconfigured exported components can lead to external intent invocation. 53 - [ ] Review **Network Security Config** (`networkSecurityConfig` XML) for `cleartextTrafficPermitted="true"` or domain-specific overrides. 54 - [ ] Look for calls to **Play Integrity / SafetyNet / DeviceCheck** – determine whether custom attestation can be hooked/bypassed. 55 - [ ] Inspect **App Links / Deep Links** (`android:autoVerify`) for intent-redirection or open-redirect issues. 56 - [ ] Identify usage of **WebView.addJavascriptInterface** or `loadData*()` that may lead to RCE / XSS inside the app. 57 - [ ] Analyse cross-platform bundles (Flutter `libapp.so`, React-Native JS bundles, Capacitor/Ionic assets). Dedicated tooling: 58 - `flutter-packer`, `fluttersign`, `rn-differ` 59 - [ ] Scan third-party native libraries for known CVEs (e.g., **libwebp CVE-2023-4863**, **libpng**, etc.). 60 - [ ] Evaluate **SEMgrep Mobile rules**, **Pithus** and the latest **MobSF ≥ 3.9** AI-assisted scan results for additional findings. 61 - [ ] Check OEM ROM add-ons (OxygenOS/ColorOS/MIUI/OneUI) for extra **exported ContentProviders** that bypass permissions; try `content query --uri content://com.android.providers.telephony/ServiceNumberProvider` without `READ_SMS` (e.g., OnePlus CVE-2025-10184).<sup>[[2]](#references)</sup> 62 63 ### [Dynamic Analysis](android-app-pentesting/index.html#dynamic-analysis) 64 65 - [ ] Prepare the environment ([online](android-app-pentesting/index.html#online-dynamic-analysis), [local VM or physical](android-app-pentesting/index.html#local-dynamic-analysis)) 66 - [ ] Is there any [unintended data leakage](android-app-pentesting/index.html#unintended-data-leakage) (logging, copy/paste, crash logs)? 67 - [ ] [Confidential information being saved in SQLite dbs](android-app-pentesting/index.html#sqlite-dbs)? 68 - [ ] [Exploitable exposed Activities](android-app-pentesting/index.html#exploiting-exported-activities-authorisation-bypass)? 69 - [ ] [Exploitable Content Providers](android-app-pentesting/index.html#exploiting-content-providers-accessing-and-manipulating-sensitive-information)? 70 - [ ] [Exploitable exposed Services](android-app-pentesting/index.html#exploiting-services)? 71 - [ ] [Exploitable Broadcast Receivers](android-app-pentesting/index.html#exploiting-broadcast-receivers)? 72 - [ ] Is the application [transmitting information in clear text/using weak algorithms](android-app-pentesting/index.html#insufficient-transport-layer-protection)? is a MitM possible? 73 - [ ] [Inspect HTTP/HTTPS traffic](android-app-pentesting/index.html#inspecting-http-traffic) 74 - [ ] This one is really important, because if you can capture the HTTP traffic you can search for common Web vulnerabilities (Hacktricks has a lot of information about Web vulns). 75 - [ ] Check for possible [Android Client Side Injections](android-app-pentesting/index.html#android-client-side-injections-and-others) (probably some static code analysis will help here) 76 - [ ] [Frida](android-app-pentesting/index.html#frida): Just Frida, use it to obtain interesting dynamic data from the application (maybe some passwords...) 77 - [ ] Test for **Tapjacking / Animation-driven attacks (TapTrap 2025)** even on Android 15+ (no overlay permission required).<sup>[[3]](#references)</sup><sup>[[4]](#references)</sup> 78 - [ ] Attempt **overlay / SYSTEM_ALERT_WINDOW clickjacking** and **Accessibility Service abuse** for privilege escalation. 79 - [ ] Check if `adb backup` / `bmgr backupnow` can still dump app data (apps that forgot to disable `allowBackup`). 80 - [ ] Probe for **Binder-level LPEs** (e.g., **CVE-2023-20963, CVE-2023-20928**); use kernel fuzzers or PoCs if permitted. 81 - [ ] If Play Integrity / SafetyNet is enforced, try runtime hooks (`Frida Gadget`, `MagiskIntegrityFix`, `Integrity-faker`) or network-level replay. Recent Play Integrity Fix forks (≥17.x) embed `playcurl`—focus on ZygiskNext + PIF + ZygiskAssistant/TrickyStore combinations to regain DEVICE/STRONG verdicts. 82 - [ ] Instrument with modern tooling: 83 - **Objection > 2.0**, **Frida 17+ (Android 16 support, ART offset fixes)**, **NowSecure-Tracer (2024)** 84 - Dynamic system-wide tracing with `perfetto` / `simpleperf`. 85 - [ ] For OEM telephony/provider bugs (e.g., OxygenOS CVE-2025-10184), attempt **permission-less SMS read/send** via the `content` CLI or in-app `ContentResolver`; test blind SQLi in `update()` to exfiltrate rows.<sup>[[2]](#references)</sup> 86 87 ### Some obfuscation/Deobfuscation information 88 89 - [ ] [Read here](android-app-pentesting/index.html#obfuscating-deobfuscating-code) 90 91 ## References 92 93 - [1] [CVE-2025-59489 – Arbitrary Code Execution in Unity Runtime (blog)](https://flatt.tech/research/posts/arbitrary-code-execution-in-unity-runtime/) 94 - [2] [Rapid7: CVE-2025-10184 OnePlus OxygenOS Telephony provider permission bypass](https://www.rapid7.com/blog/post/cve-2025-10184-oneplus-oxygenos-telephony-provider-permission-bypass-not-fixed/) 95 - [3] [This new Android attack could trick you into compromising your own phone (Tom's Guide, on TapTrap)](https://www.tomsguide.com/computing/online-security/this-new-android-attack-could-trick-you-into-compromising-your-own-phone-everything-you-need-to-know) 96 - [4] [TapTrap: Animation-Driven Tapjacking on Android (TU Wien / USENIX Security 2025)](https://taptrap.click/) 97 - [5] [OWASP Mobile Application Security Testing Guide - Android](https://mas.owasp.org/MASTG/0x05b-Android-Security-Testing/)