ios-pentesting-checklist.md (11456B)
1 --- 2 title: "iOS Pentesting Checklist" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/ios-pentesting-checklist.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/ios-pentesting-checklist.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # iOS Pentesting Checklist 14 15 ### Preparation 16 17 - [ ] Read [**iOS Basics**](/hacktricks/mobile-pentesting/ios-pentesting/ios-basics) 18 - [ ] Read [**iOS Basic Testing Operations**](/hacktricks/mobile-pentesting/ios-pentesting/basic-ios-testing-operations) to learn current extraction, installation, and filesystem access workflows 19 - [ ] Prepare your environment reading [**iOS Testing Environment**](/hacktricks/mobile-pentesting/ios-pentesting/ios-testing-environment) 20 - [ ] If you are testing on **iOS 16+**, enable **Developer Mode** and decide if you need a simulator, a paired physical device (`xcrun devicectl`), or a jailbroken/rootless device 21 - [ ] If a jailbreak isn't available, review [**iOS Pentesting without Jailbreak**](/hacktricks/mobile-pentesting/ios-pentesting/ios-pentesting-without-jailbreak) 22 - [ ] Read all the sections of [**iOS Initial Analysis**](ios-pentesting/index.html#initial-analysis) to learn common actions to pentest an iOS application 23 - [ ] Extract [**entitlements**](/hacktricks/mobile-pentesting/ios-pentesting/extracting-entitlements-from-compiled-application) early and review **Associated Domains**, **App Groups**, **keychain access groups**, extension points, `get-task-allow`, and unusual capabilities 24 - [ ] Review `Info.plist` for `CFBundleURLTypes`, `LSApplicationQueriesSchemes`, `NSAppTransportSecurity`, `WKAppBoundDomains`, and `.appex` extension declarations 25 26 ### Data Storage 27 28 - [ ] [**Plist files**](ios-pentesting/index.html#plist) can be used to store sensitive information. 29 - [ ] [**Core Data**](ios-pentesting/index.html#core-data) (SQLite database) can store sensitive information. 30 - [ ] [**YapDatabases**](ios-pentesting/index.html#yapdatabase) (SQLite database) can store sensitive information. 31 - [ ] [**Firebase**](ios-pentesting/index.html#firebase-real-time-databases) misconfiguration. 32 - [ ] [**Realm databases**](ios-pentesting/index.html#realm-databases) can store sensitive information. 33 - [ ] [**Couchbase Lite databases**](ios-pentesting/index.html#couchbase-lite-databases) can store sensitive information. 34 - [ ] [**Binary cookies**](ios-pentesting/index.html#cookies) can store sensitive information 35 - [ ] [**Cache data**](ios-pentesting/index.html#cache) can store sensitive information 36 - [ ] [**Automatic snapshots**](ios-pentesting/index.html#snapshots) can save visual sensitive information 37 - [ ] [**Keychain**](ios-pentesting/index.html#keychain) is usually used to store sensitive information that can be left when reselling the phone. 38 - [ ] If the app uses **App Groups**, inspect the **shared container** and **shared preferences** reachable by the main app, widgets, and share extensions<sup>[[1]](#references)</sup> 39 - [ ] Review **Data Protection / NSFileProtection** classes in both the app container and any group container, especially files left as `NSFileProtectionNone` or `NSFileProtectionCompleteUntilFirstUserAuthentication` 40 - [ ] Review **Keychain** item protections (`kSecAttrAccessible*`, `SecAccessControl`) and any **keychain access groups**; secrets intended to be device/biometry-bound should use restrictive flags such as `ThisDeviceOnly` / `biometryCurrentSet` 41 - [ ] In summary, just **check for sensitive information saved by the application in the filesystem** 42 43 ### Keyboards 44 45 - [ ] Does the application [**allow the use of custom keyboards**](ios-pentesting/index.html#custom-keyboards-keyboard-cache)? 46 - [ ] Check if sensitive information is saved in the [**keyboards cache files**](ios-pentesting/index.html#custom-keyboards-keyboard-cache) 47 48 ### **Logs** 49 50 - [ ] Check if [**sensitive information is being logged**](ios-pentesting/index.html#logs) 51 - [ ] Check **unified logging** and crash artifacts in addition to app-controlled logs, especially after login, token refresh, deep link handling, and WebView activity 52 53 ### Backups 54 55 - [ ] [**Backups**](ios-pentesting/index.html#backups) can be used to **access sensitive information** saved in the file system (check the initial point of this checklist) 56 - [ ] Also, [**backups**](ios-pentesting/index.html#backups) can be used to **modify some configurations of the application**, then **restore** the backup on the phone, and then as the **modified configuration** is **loaded** some (security) **functionality** may be **bypassed** 57 - [ ] Verify whether secrets expected to be **device-only** or **non-migratable** survive backup / restore or device-to-device migration because the app uses a migratable Keychain class 58 59 ### **Applications Memory** 60 61 - [ ] Check for sensitive information inside the [**application's memory**](ios-pentesting/index.html#testing-memory-for-sensitive-data) 62 63 ### **Broken Cryptography** 64 65 - [ ] Check if you can find [**passwords used for cryptography**](ios-pentesting/index.html#broken-cryptography) 66 - [ ] Check for the use of [**deprecated/weak algorithms**](ios-pentesting/index.html#broken-cryptography) to send/store sensitive data 67 - [ ] [**Hook and monitor cryptography functions**](ios-pentesting/index.html#broken-cryptography) 68 69 ### **Local Authentication** 70 71 - [ ] If a [**local authentication**](ios-pentesting/index.html#local-authentication) is used in the application, you should check how the authentication is working. 72 - [ ] If the app treats a successful [**Local Authentication Framework**](ios-pentesting/index.html#local-authentication-framework) callback as the only authorization check, test whether hooking that callback bypasses the gate. Stronger designs bind access to a Keychain key protected by `SecAccessControl` rather than trusting a Boolean result alone. 73 - [ ] If it's using a [**function that can be dynamically bypassed**](ios-pentesting/index.html#local-authentication-using-keychain) you could create a custom Frida script 74 - [ ] Check for **`LAContext` reuse** / `touchIDAuthenticationAllowableReuseDuration` so sensitive actions succeed because the device was recently unlocked instead of triggering a fresh biometric prompt 75 - [ ] If keychain items are unlocked with biometrics, verify whether biometric enrollment changes invalidate them (`biometryCurrentSet`) or if they remain accessible unexpectedly 76 77 ### Sensitive Functionality Exposure Through IPC 78 79 - [**Custom URI Handlers / Deeplinks / Custom Schemes**](ios-pentesting/index.html#custom-uri-handlers-deeplinks-custom-schemes) 80 - [ ] Check if the application is **registering any protocol/scheme** 81 - [ ] Check if the application is **registering to use** any protocol/scheme 82 - [ ] Check if the application **expects to receive any kind of sensitive information** from the custom scheme that can be **intercepted** by another application registering the same scheme 83 - [ ] Check if the application **isn't checking and sanitizing** user input via the custom scheme and some **vulnerability can be exploited** 84 - [ ] Check if the application **exposes any sensitive action** that can be called from anywhere via the custom scheme 85 - [ ] If OAuth / SSO callbacks use **custom schemes**, test **scheme hijacking** with a malicious app and prefer claimed `https` / Universal Links for auth callbacks 86 - [**Universal Links**](ios-pentesting/index.html#universal-links) 87 - [ ] Check if the application is **registering any universal protocol/scheme** 88 - [ ] Check the `apple-app-site-association` file 89 - [ ] Audit the AASA for **wildcards / over-broad `paths` or `components`** and sensitive or unpublished routes 90 - [ ] Verify undefined routes that still match AASA rules return **404** and that wildcard subdomains are not over-trusted 91 - [ ] Check if the application **isn't checking and sanitizing** user input via the universal link and some **vulnerability can be exploited** 92 - [ ] Check if the application **exposes any sensitive action** that can be called from anywhere via the universal link 93 - [**UIActivity Sharing**](/hacktricks/mobile-pentesting/ios-pentesting/ios-uiactivity-sharing) 94 - [ ] Check if the application can receive UIActivities and if it's possible to exploit any vulnerability with specially crafted activity 95 - [**UIPasteboard**](/hacktricks/mobile-pentesting/ios-pentesting/ios-uipasteboard) 96 - [ ] Check if the application is **copying anything to the general pasteboard** 97 - [ ] Check if the application is **using the data from the general pasteboard for anything** 98 - [ ] Monitor the pasteboard to see if any **sensitive data is copied** 99 - [**App Extensions**](/hacktricks/mobile-pentesting/ios-pentesting/ios-app-extensions) 100 - [ ] Is the application **using any extension**? 101 - [ ] Enumerate every `.appex`, inspect `NSExtensionActivationRule`, and map which **App Group** / shared container each extension can reach 102 - [**WebViews**](/hacktricks/mobile-pentesting/ios-pentesting/ios-webviews) 103 - [ ] Check which kind of webviews are being used 104 - [ ] Check the status of **`javaScriptEnabled`**, **`JavaScriptCanOpenWindowsAutomatically`**, **`hasOnlySecureContent`** 105 - [ ] Check if the webview can **access local files** with the protocol **`file://`** (`allowFileAccessFromFileURLs`, `allowUniversalAccessFromFileURLs`) 106 - [ ] Check if JavaScript can access **native methods** (`JSContext`, `postMessage`) 107 - [ ] Check if the app opted into `WKAppBoundDomains` / `limitsNavigationsToAppBoundDomains` when using hybrid content or privileged JS bridges<sup>[[2]](#references)</sup> 108 - [ ] If `WKScriptMessageHandler` / `postMessage` bridges exist, confirm they validate the **current URL/origin/frame** before dispatching privileged native functionality 109 - [ ] Check whether `WKWebView.isInspectable` / `JSContext.isInspectable` is enabled in production builds or can be flipped at runtime to inspect embedded JavaScript 110 111 ### Network Communication 112 113 - [ ] Perform a [**MitM to the communication**](ios-pentesting/index.html#network-communication) and search for web vulnerabilities. 114 - [ ] Check if the [**hostname of the certificate**](ios-pentesting/index.html#hostname-check) is checked 115 - [ ] Check/Bypass [**Certificate Pinning**](ios-pentesting/index.html#certificate-pinning) 116 - [ ] Review `NSAppTransportSecurity` for `NSAllowsArbitraryLoads`, `NSAllowsArbitraryLoadsInWebContent`, `NSAllowsLocalNetworking`, per-domain `NSExceptionDomains`, and legacy `NSTemporaryException*` keys 117 - [ ] If the app uses lower-level sockets, IP literals, or `.local` hosts, test those flows separately because ATS protections may not apply 118 119 ### **Misc** 120 121 - [ ] Check for [**automatic patching/updating**](ios-pentesting/index.html#hot-patching-enforced-updateing) mechanisms 122 - [ ] Check for [**malicious third party libraries**](ios-pentesting/index.html#third-parties) 123 - [ ] Review third-party SDKs / hybrid frameworks for embedded **WebViews**, **App Groups**, **custom URL schemes**, analytics beacons, or hot-patching logic that silently widens the attack surface 124 125 ## References 126 127 - [1] [Apple Platform Security: App protection and app groups in iOS, iPadOS, and visionOS](https://support.apple.com/en-us/guide/security/sec1a976c067/web) 128 - [2] [WebKit: App-Bound Domains](https://webkit.org/blog/10882/app-bound-domains/)