> For the complete documentation index, see [llms.txt](https://book.konstantinsecurity.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://book.konstantinsecurity.com/readme/pentest/ios.md).

# iOS

<https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting-checklist>

![](/files/Op0SY7pAoEYCelyWAK0s)

### Preparation

* Read [**iOS Basics**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting/ios-basics)
* Prepare your environment reading [**iOS Testing Environment**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting/ios-testing-environment)
* Read all the sections of [**iOS Initial Analysis**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#initial-analysis) to learn common actions to pentest an iOS application

### Data Storage

* [**Plist files**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#plist) can be used to store sensitive information.
* [**Core Data**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#core-data) (SQLite database) can store sensitive information.
* [**YapDatabases**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#yapdatabase) (SQLite database) can store sensitive information.
* [**Firebase**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#firebase-real-time-databases) miss-configuration.
* [**Realm databases**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#realm-databases) can store sensitive information.
* [**Couchbase Lite databases**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#couchbase-lite-databases) can store sensitive information.
* [**Binary cookies**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#cookies) can store sensitive information
* [**Cache data**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#cache) can store sensitive information
* [**Automatic snapshots**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#snapshots) can save visual sensitive information
* [**Keychain**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#keychain) is usually used to store sensitive information that can be left when reselling the phone.
* In summary, just **check for sensitive information saved by the application in the filesystem**

### Keyboards

* Does the application [**allow to use custom keyboards**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#custom-keyboards-keyboard-cache)?
* Check if sensitive information is saved in the [**keyboards cache files**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#custom-keyboards-keyboard-cache)

### **Logs**

* Check if [**sensitive information is being logged**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#logs)

### Backups

* [**Backups**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#backups) can be used to **access the sensitive information** saved in the file system (check the initial point of this checklist)
* Also, [**backups**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#backups) can be used to **modify some configurations of the application**, then **restore** the backup on the phone, and the as the **modified configuration** is **loaded** some (security) **functionality** may be **bypassed**

### **Applications Memory**

* Check for sensitive information inside the [**application's memory**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#testing-memory-for-sensitive-data)

### **Broken Cryptography**

* Check if yo can find [**passwords used for cryptography**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#broken-cryptography)
* Check for the use of [**deprecated/weak algorithms**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#broken-cryptography) to send/store sensitive data
* [**Hook and monitor cryptography functions**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#broken-cryptography)

### **Local Authentication**

* If a [**local authentication**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#local-authentication) is used in the application, you should check how the authentication is working.
  * If it's using the [**Local Authentication Framework**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#local-authentication-framework) it could be easily bypassed
  * If it's using a [**function that can dynamically bypassed**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#local-authentication-using-keychain) you could create a custom frida script

### Sensitive Functionality Exposure Through IPC

* [**Custom URI Handlers / Deeplinks / Custom Schemes**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#custom-uri-handlers-deeplinks-custom-schemes)
  * Check if the application is **registering any protocol/scheme**
  * Check if the application is **registering to use** any protocol/scheme
  * Check if the application **expects to receive any kind of sensitive information** from the custom scheme that can be **intercepted** by the another application registering the same scheme
  * Check if the application **isn't checking and sanitizing** users input via the custom scheme and some **vulnerability can be exploited**
  * Check if the application **exposes any sensitive action** that can be called from anywhere via the custom scheme
* [**Universal Links**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#universal-links)
  * Check if the application is **registering any universal protocol/scheme**
  * Check the `apple-app-site-association` file
  * Check if the application **isn't checking and sanitizing** users input via the custom scheme and some **vulnerability can be exploited**
  * Check if the application **exposes any sensitive action** that can be called from anywhere via the custom scheme
* [**UIActivity Sharing**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting/ios-uiactivity-sharing)
  * Check if the application can receive UIActivities and if it's possible to exploit any vulnerability with specially crafted activity
* [**UIPasteboard**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting/ios-uipasteboard)
  * Check if the application if **copying anything to the general pasteboard**
  * Check if the application if **using the data from the general pasteboard for anything**
  * Monitor the pasteboard to see if any **sensitive data is copied**
* [**App Extensions**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting/ios-app-extensions)
  * Is the application **using any extension**?
* [**WebViews**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting/ios-webviews)
  * Check which kind of webviews are being used
  * Check the status of **`javaScriptEnabled`**, **`JavaScriptCanOpenWindowsAutomatically`**, **`hasOnlySecureContent`**
  * Check if the webview can **access local files** with the protocol **file://** **(**`allowFileAccessFromFileURLs`, `allowUniversalAccessFromFileURLs`)
  * Check if Javascript can access **Native** **methods** (`JSContext`, `postMessage`)

### Network Communication

* Perform a [**MitM to the communication**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#network-communication) and search for web vulnerabilities.
* Check if the [**hostname of the certificate**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#hostname-check) is checked
* Check/Bypass [**Certificate Pinning**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#certificate-pinning)

### **Misc**

* Check for [**automatic patching/updating**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#hot-patching-enforced-updateing) mechanisms
* Check for [**malicious third party libraries**](https://book.hacktricks.xyz/mobile-pentesting/ios-pentesting#third-parties)

[SSL unpinning iOS and macOS applications](/readme/pentest/ios/ssl-unpinning-ios-and-macos-applications.md)
