daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

android-checklist.md (9106B)


      1 ---
      2 title: "Android APK Checklist"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/android-checklist.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-checklist.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Android APK Checklist
     14 
     15 This checklist complements the OWASP Mobile Application Security Testing Guide; apply each item according to the application's threat model and authorized test scope.<sup>[[5]](#references)</sup>
     16 
     17 ### [Learn Android fundamentals](android-app-pentesting/index.html#2-android-application-fundamentals)
     18 
     19 - [ ] [Basics](android-app-pentesting/index.html#fundamentals-review)
     20 - [ ] [Dalvik & Smali](android-app-pentesting/index.html#dalvik--smali)
     21 - [ ] [Entry points](android-app-pentesting/index.html#application-entry-points)
     22   - [ ] [Activities](android-app-pentesting/index.html#launcher-activity)
     23   - [ ] [URL Schemes](android-app-pentesting/index.html#url-schemes)
     24   - [ ] [Content Providers](android-app-pentesting/index.html#services)
     25   - [ ] [Services](android-app-pentesting/index.html#services-1)
     26   - [ ] [Broadcast Receivers](android-app-pentesting/index.html#broadcast-receivers)
     27   - [ ] [Intents](android-app-pentesting/index.html#intents)
     28   - [ ] [Intent Filter](android-app-pentesting/index.html#intent-filter)
     29 - [ ] [Other components](android-app-pentesting/index.html#other-app-components)
     30 - [ ] [How to use ADB](android-app-pentesting/index.html#adb-android-debug-bridge)
     31 - [ ] [How to modify Smali](android-app-pentesting/index.html#smali)
     32 
     33 ### [Static Analysis](android-app-pentesting/index.html#static-analysis)
     34 
     35 - [ ] Check for [obfuscation](/hacktricks/mobile-pentesting/android-checklist#some-obfuscation-deobfuscation-information), root/emulator detection, and anti-tampering checks. [Read this for more information](android-app-pentesting/index.html#other-checks).
     36 - [ ] Sensitive applications (like bank apps) should check if the mobile is rooted and should actuate in consequence.
     37 - [ ] Search for [interesting strings](android-app-pentesting/index.html#looking-for-interesting-info) (passwords, URLs, API, encryption, backdoors, tokens, Bluetooth uuids...).
     38   - [ ] Special attention to [firebase ](android-app-pentesting/index.html#firebase)APIs.
     39 - [ ] [Read the manifest:](android-app-pentesting/index.html#basic-understanding-of-the-application-manifest-xml)
     40   - [ ] Check if the application is in debug mode and try to "exploit" it
     41   - [ ] Check if the APK allows backups
     42   - [ ] Exported Activities
     43     - [ ] Unity Runtime: exported UnityPlayerActivity/UnityPlayerGameActivity with a `unity` CLI extras bridge. Test `-xrsdk-pre-init-library <abs-path>` for pre-init `dlopen()` RCE. See [Intent Injection → Unity Runtime](/hacktricks/mobile-pentesting/android-app-pentesting/intent-injection).<sup>[[1]](#references)</sup>
     44   - [ ] Content Providers
     45   - [ ] Exposed services
     46   - [ ] Broadcast Receivers
     47   - [ ] URL Schemes
     48 - [ ] Is the application [saving data insecurely, internally or externally](android-app-pentesting/index.html#insecure-data-storage)?
     49 - [ ] Is any [password hard-coded or saved on disk](android-app-pentesting/index.html#poorkeymanagementprocesses)? Is the app [using insecure cryptographic algorithms](android-app-pentesting/index.html#useofinsecureandordeprecatedalgorithms)?
     50 - [ ] Are all native libraries compiled as PIE where the platform requires it?
     51 - [ ] Use [static Android analyzers](android-app-pentesting/index.html#automatic-analysis) to complement manual review.
     52 - [ ] `android:exported` **mandatory on Android 12+** – misconfigured exported components can lead to external intent invocation.
     53 - [ ] Review **Network Security Config** (`networkSecurityConfig` XML) for `cleartextTrafficPermitted="true"` or domain-specific overrides.
     54 - [ ] Look for calls to **Play Integrity / SafetyNet / DeviceCheck** – determine whether custom attestation can be hooked/bypassed.
     55 - [ ] Inspect **App Links / Deep Links** (`android:autoVerify`) for intent-redirection or open-redirect issues.
     56 - [ ] Identify usage of **WebView.addJavascriptInterface** or `loadData*()` that may lead to RCE / XSS inside the app.
     57 - [ ] Analyse cross-platform bundles (Flutter `libapp.so`, React-Native JS bundles, Capacitor/Ionic assets). Dedicated tooling:
     58   - `flutter-packer`, `fluttersign`, `rn-differ`
     59 - [ ] Scan third-party native libraries for known CVEs (e.g., **libwebp CVE-2023-4863**, **libpng**, etc.).
     60 - [ ] Evaluate **SEMgrep Mobile rules**, **Pithus** and the latest **MobSF ≥ 3.9** AI-assisted scan results for additional findings.
     61 - [ ] Check OEM ROM add-ons (OxygenOS/ColorOS/MIUI/OneUI) for extra **exported ContentProviders** that bypass permissions; try `content query --uri content://com.android.providers.telephony/ServiceNumberProvider` without `READ_SMS` (e.g., OnePlus CVE-2025-10184).<sup>[[2]](#references)</sup>
     62 
     63 ### [Dynamic Analysis](android-app-pentesting/index.html#dynamic-analysis)
     64 
     65 - [ ] Prepare the environment ([online](android-app-pentesting/index.html#online-dynamic-analysis), [local VM or physical](android-app-pentesting/index.html#local-dynamic-analysis))
     66 - [ ] Is there any [unintended data leakage](android-app-pentesting/index.html#unintended-data-leakage) (logging, copy/paste, crash logs)?
     67 - [ ] [Confidential information being saved in SQLite dbs](android-app-pentesting/index.html#sqlite-dbs)?
     68 - [ ] [Exploitable exposed Activities](android-app-pentesting/index.html#exploiting-exported-activities-authorisation-bypass)?
     69 - [ ] [Exploitable Content Providers](android-app-pentesting/index.html#exploiting-content-providers-accessing-and-manipulating-sensitive-information)?
     70 - [ ] [Exploitable exposed Services](android-app-pentesting/index.html#exploiting-services)?
     71 - [ ] [Exploitable Broadcast Receivers](android-app-pentesting/index.html#exploiting-broadcast-receivers)?
     72 - [ ] Is the application [transmitting information in clear text/using weak algorithms](android-app-pentesting/index.html#insufficient-transport-layer-protection)? is a MitM possible?
     73 - [ ] [Inspect HTTP/HTTPS traffic](android-app-pentesting/index.html#inspecting-http-traffic)
     74   - [ ] This one is really important, because if you can capture the HTTP traffic you can search for common Web vulnerabilities (Hacktricks has a lot of information about Web vulns).
     75 - [ ] Check for possible [Android Client Side Injections](android-app-pentesting/index.html#android-client-side-injections-and-others) (probably some static code analysis will help here)
     76 - [ ] [Frida](android-app-pentesting/index.html#frida): Just Frida, use it to obtain interesting dynamic data from the application (maybe some passwords...)
     77 - [ ] Test for **Tapjacking / Animation-driven attacks (TapTrap 2025)** even on Android 15+ (no overlay permission required).<sup>[[3]](#references)</sup><sup>[[4]](#references)</sup>
     78 - [ ] Attempt **overlay / SYSTEM_ALERT_WINDOW clickjacking** and **Accessibility Service abuse** for privilege escalation.
     79 - [ ] Check if `adb backup` / `bmgr backupnow` can still dump app data (apps that forgot to disable `allowBackup`).
     80 - [ ] Probe for **Binder-level LPEs** (e.g., **CVE-2023-20963, CVE-2023-20928**); use kernel fuzzers or PoCs if permitted.
     81 - [ ] If Play Integrity / SafetyNet is enforced, try runtime hooks (`Frida Gadget`, `MagiskIntegrityFix`, `Integrity-faker`) or network-level replay. Recent Play Integrity Fix forks (≥17.x) embed `playcurl`—focus on ZygiskNext + PIF + ZygiskAssistant/TrickyStore combinations to regain DEVICE/STRONG verdicts.
     82 - [ ] Instrument with modern tooling:
     83   - **Objection > 2.0**, **Frida 17+ (Android 16 support, ART offset fixes)**, **NowSecure-Tracer (2024)**
     84   - Dynamic system-wide tracing with `perfetto` / `simpleperf`.
     85 - [ ] For OEM telephony/provider bugs (e.g., OxygenOS CVE-2025-10184), attempt **permission-less SMS read/send** via the `content` CLI or in-app `ContentResolver`; test blind SQLi in `update()` to exfiltrate rows.<sup>[[2]](#references)</sup>
     86 
     87 ### Some obfuscation/Deobfuscation information
     88 
     89 - [ ] [Read here](android-app-pentesting/index.html#obfuscating-deobfuscating-code)
     90 
     91 ## References
     92 
     93 - [1] [CVE-2025-59489 – Arbitrary Code Execution in Unity Runtime (blog)](https://flatt.tech/research/posts/arbitrary-code-execution-in-unity-runtime/)
     94 - [2] [Rapid7: CVE-2025-10184 OnePlus OxygenOS Telephony provider permission bypass](https://www.rapid7.com/blog/post/cve-2025-10184-oneplus-oxygenos-telephony-provider-permission-bypass-not-fixed/)
     95 - [3] [This new Android attack could trick you into compromising your own phone (Tom's Guide, on TapTrap)](https://www.tomsguide.com/computing/online-security/this-new-android-attack-could-trick-you-into-compromising-your-own-phone-everything-you-need-to-know)
     96 - [4] [TapTrap: Animation-Driven Tapjacking on Android (TU Wien / USENIX Security 2025)](https://taptrap.click/)
     97 - [5] [OWASP Mobile Application Security Testing Guide - Android](https://mas.owasp.org/MASTG/0x05b-Android-Security-Testing/)