Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Test a mobile app on real devices by first defining the app’s threat model and authorized scope, then mapping applicable OWASP MASVS controls to MASTG checks, and finally exercising the relevant workflows on representative Android and iOS phones. Combine repeatable automated checks with manual testing of real user flows, backend requests, local data, and platform entry points. A single device or a clean test run cannot establish that an app is secure; the result is evidence about the controls and configurations you actually tested.

1. Define what you are authorized to test

Before installing a build, agree in writing on the app, test accounts, backend environment, test data, and actions in scope. Mobile testing can affect real accounts or services if a production build or backend is used inadvertently.

  • Record the app name, build or version identifier, package or bundle identifier, and intended configuration.
  • Use a designated test backend and synthetic data. Identify any services or systems that are explicitly out of scope.
  • List the account roles and permissions you need, including ordinary and privileged roles where applicable.
  • Record supported operating-system versions and device capabilities relevant to the app.
  • Agree whether instrumentation is allowed and whether each device must be stock, rooted, or jailbroken. Treat modified-device testing as a separate condition, not as a substitute for a stock-device run.
  • Set rules for handling evidence: avoid real user data, protect credentials and tokens, and redact sensitive values from reports.

For each device, record the manufacturer and model, OS version, device state, app build, and test date. “Real device” should mean an identified physical phone in a known state, rather than an unspecified handset.

2. Choose controls and tests that fit the app

OWASP’s Mobile Application Security Verification Standard (MASVS) gives you a framework for security requirements; its Mobile Application Security Testing Guide (MASTG) provides testing guidance and cases for examining those requirements. Use them together to move from “what should be protected?” to “how will we check it?” Their checklists can support manual assessments and help structure automation, but not every check applies to every app.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yojaro 4Pack Silicone Suction Phone Case Mount, Silicon Adhesive Smartphones Stand Sticky, Hands-Free Phone Accessories Holder for Selfies and Videos (Black & White & Translucent & Light Pink)
  • 【Strong Adsorption】The inspiration of the silicone phone suction case comes from the adhesive force of the octopus. Each suction cup phone mount is 3.15 inches long and 2.17 inches wide, with 24 independent suction cups providing a stronger and more stable suction force, so you don't have to worry about your phone falling during use.
  • 【Back of Phone Suction Grip】Remove the adhesive film on the phone suction cup and stick it on the phone case. You can then fix the phone on any smooth surface, which is very convenient. (The phone suction cup cannot be removed and reused after being attached to the phone case. It is recommended to attach it to a regular phone case, not a valuable one.)
  • 【Widely Used】Our non-slip silicone phone sticky grip mount attaches to almost any flat phone case and make it compatible with common mobile phones such as iPhone and Android.You can shoot, watch videos or video calls in the kitchen, gym, dance studio, bathroom and other places.
  • 【Capture the Wonderful Picture】Whether you are a TikTok creator or just like to share videos and photos, this phone suction cup can help you hands-free capture wonderful videos and photos for sharing with friends.
  • 【Note】You can fix the phone suction cup on a smooth surface such as a mirror or glass. If necessary, wipe the suction cup with a damp cloth to obtain stronger suction. Before releasing your hand, make sure the phone is firmly fixed. (Not applicable to rough walls, wooden surfaces, and other uneven surfaces)

Select checks based on the app’s architecture, data sensitivity, features, and threat model. MASVS groups include storage, cryptography, authentication and authorization, network communication, platform interaction, code quality, resilience, and privacy. MASTG has general guidance and Android- and iOS-specific material. Many techniques can also apply to hybrid or web-based mobile apps because they use native components.

App characteristic Areas to include in the plan Example evidence to retain
Sensitive data is stored or displayed Local storage, logs, screenshots and app-switcher snapshots, backups, keyboard suggestions, and data shared with other apps Test action, storage location or observation, data sensitivity, and protection observed
Users sign in or have different roles Authentication, session handling, reauthentication, account switching, and backend authorization Role, request or action attempted, response, and whether access was correctly granted or denied
The app communicates with remote services TLS configuration, certificate validation, and confidentiality and integrity of exchanged data Relevant request/response behavior, network conditions, and visibility limits of the test setup
The app uses operating-system features or talks to other apps Permissions, deep links, Android intents, iOS universal links, extensions, widgets, shortcuts, and inter-process communication Entry point, device state, caller or input, and resulting screen or action
The app has integrity or anti-tampering controls Build configuration, dependencies, debug settings, binary integrity, and threat-model-relevant resilience checks Build and device state, check performed, and control behavior observed

For each selected check, note the related MASVS expectation and MASTG test or technique. Mark a check “not applicable” only with a brief reason tied to the app’s design; distinguish it from “not tested.”

3. Select representative Android and iOS devices

Choose devices that reflect the platforms and OS versions the app claims to support, plus capabilities the app actually uses. There is no universal device count or single best phone established by OWASP’s guidance. The aim is to cover meaningful differences, not to collect models without a reason.

Rank #2
Apple EarPods Headphones with USB-C Plug, Wired Ear Buds with Built-in Remote to Control Music, Phone Calls, and Volume
  • SUPERIOR COMFORT — Unlike traditional circular ear buds, the design of EarPods is defined by the geometry of the ear. Which makes them more comfortable for more people than any other ear bud–style headphones.
  • HIGH-QUALITY AUDIO — The speakers inside EarPods have been engineered to maximize sound output and minimize sound loss, which means you get high-quality audio.
  • BUILT-IN REMOTE — EarPods with USB-C plug also include a built-in remote that lets you adjust the volume, control the playback of music and video, and answer or end calls with a pinch of the cord.
  • COMPATIBILITY — Works with all devices that have a USB-C port.
  • INTEGRATED MICROPHONE — A built-in microphone precisely captures your voice while you’re on the phone, taking a FaceTime call, or summoning Siri — so you’re always heard loud and clear.
  • Android: account for manufacturer and OS variation. Hardware-backed secure storage is not available on every Android device, and some devices run older Android versions. Record the relevant hardware-backed key and biometric capabilities rather than assuming they exist.
  • iOS: include supported OS versions and the hardware or platform features your app relies on, such as biometrics, app extensions, or universal links.
  • Both platforms: add NFC, camera, eSIM, or accessory coverage only when the app uses those capabilities. Include both stock and modified states only when the test scope calls for them.

Emulators and simulators are useful for development and repeatable checks, but they do not demonstrate behavior on physical hardware. Use them as supplements, not as evidence of real-device hardware behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Test local data and privacy behavior

Use a dedicated test account and follow realistic flows that create, view, update, and remove sensitive information. Check both normal completion and interruption: force-close or restart the app, lock and unlock the phone, switch apps, and sign out. Inspect what the authorized test setup can access in files, databases, preferences, logs, caches, and other relevant locations.

  1. Identify the data the app handles and classify what would be sensitive if exposed.
  2. Perform a specific workflow that creates or uses that data, then inspect the relevant storage and platform surfaces.
  3. Check whether sensitive values remain in logs, caches, keyboard suggestions, screenshots or app-switcher snapshots, backups, or data exposed to other apps.
  4. Test whether logout, account switching, or deletion removes or appropriately protects data that should no longer be available.
  5. Record the action, location, device state, observation, and mapped MASVS/MASTG check. Use synthetic data only in the report.

Evaluate storage and key handling against the app’s requirements and platform-appropriate APIs. A file that is not plainly readable in one inspection method is not, by itself, proof that all copies of the data are protected.

Rank #3
PopSockets Adhesive Phone Grip, Holder- Black
  • Secure Hold: Our PopSockets adhesive phone grip gives your cell phone a secure, comfortable hold in hand to help prevent drops while texting, taking photos, or scrolling on the go. Designed to stick firmly to most phone cases and devices.
  • Hands-Free Made Easy: Easily turn your PopSocket into a phone stand to prop up your phone anywhere, perfect for watching videos, video calls, or following recipes. A must-have phone holder that keeps your device secure and ready for anything.
  • Compatibility: Works with all phones, tablets, and Kindles. Sticks best to smooth, hard plastic cases and may not adhere to silicone or textured cases. Easily swap your PopTop to change up your style.
  • Black PopSockets: Simple, refined, and endlessly versatile. A timeless essential for any phone.
  • Travel Must-Have for People On the Go: A must-have travel accessory for flights, flying, airports, air travel, airplanes, planes, international trips, cruises, and long travel days. Key gadget for your airport haul, travel accessories and must-haves.

5. Exercise authentication, sessions, and backend authorization

Test the complete identity lifecycle, not just whether the login screen accepts credentials. Include login and logout, session renewal and expiry, app restart, device lock and unlock, biometric unlock and fallback, account switching, and role changes. Where relevant, test sensitive actions such as changing credentials or payment settings and determine whether they require reauthentication.

  • Check what happens when a session expires while the app is open, in the background, or making a request.
  • In the authorized test environment, try a request with missing, expired, or altered session credentials and observe whether the backend rejects it.
  • Verify that changing a user’s role or revoking access takes effect on server-side actions, not only in the client interface.
  • Check that signing out or revoking a session prevents its further use as intended.

Do not treat a hidden button or a client-side role check as authorization. A client can be modified or its requests can be sent outside the app; sensitive actions must be checked by the backend. OWASP’s mobile guidance also emphasizes secure session handling, revocable tokens, and reauthentication for sensitive actions.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Inspect network behavior without over-interpreting the capture

With authorization and an approved test setup, inspect traffic between the app and its services. Check that sensitive exchanges use protected transport and that certificate validation behaves as intended. Exercise relevant network changes and error conditions, and look for sensitive data exposed in requests, responses, or diagnostics.

Rank #4
360° Rotating Stainless Steel Phone Tether Tab (Silvery 3-Pack) - Universal for iPhone & Other Phones (Fits Wristbands/Necklaces/Crossbody Straps)
  • [360 ° Flexible Rotation Design] Comes with a rotatable lanyard ring that supports 360 ° free rotation, effectively solving the problem of twisted and tangled lanyards
  • [Wide compatibility] The ultra-thin 0.02-inch design does not block the charging port at all, and both wired and wireless charging can be used directly without removing the pad. Compatible with most smartphones such as iPhone, compatible with various wristbands, lanyards, crossbody straps, and keychains
  • [Durable and Portable Material] Premium rust-resistant stainless steel material with good flexibility, which not only avoids scratching the phone case, but also has excellent anti rust and anti fading performance
  • [Multi scenario Practical] Paired with a lanyard or wristband, hands-free use can be achieved. The phone is within reach and not easily dropped, ideal for daily commuting and outdoor activities. Suitable for full coverage phone cases, does not support half coverage phone cases
  • [Quality Service] If you find any damage or other issues with the product upon receipt, please contact us immediately. We will handle it quickly

A proxy’s inability to display traffic does not prove the connection is secure: certificate pinning, mutual TLS, or the test configuration may prevent observation. Record what the setup could and could not inspect. If the app uses certificate pinning, assess it against the threat model and operational requirements; pinning is not a universal requirement, and bypassing it is not an end in itself.

7. Test platform entry points and app boundaries

Inventory the platform mechanisms the app actually uses, then try them in relevant states: signed out, signed in, and with the device locked where practical. Test deep links, universal links, Android intents, permissions, app extensions, widgets, shortcuts, and other integrations for unintended access or data exposure.

  • Try expected and malformed URL or intent parameters, including links that target sensitive screens or actions.
  • Check whether an unauthenticated or locked-device entry path exposes sensitive content or performs an action without the expected confirmation.
  • Assess whether another app can trigger functionality or read data that should remain private.
  • For iOS, include relevant Siri shortcuts, widgets, and app extensions; for Android, include the intents and inter-process communication mechanisms the app exports or consumes.

Keep the test specific to actual integrations: an unused platform feature is not a meaningful test target.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Anteel 2 Pack Silicone Suction Cup Phone Case Mount Double Sided, Hands-Free Silicon Phone Grip with Higher Suction Power for Selfies and Videos, Non Slip Phone Accessories (LightPink&White)
  • 【PKYAA Double Sided Silicone Suction Phone Case Mount】PKYAA With Double Sided 40 Strong and Reliable individual suction cups, PKYAA provides a thicken and upgraded universal silicon suction mount for your phone.
  • 【Friendly to Content Creators】If you are a content creator or an online influencer, you can create videos anywhere with this suction mount completely hands free with this silicone cell phone mount for cases.
  • 【HANDS-FREE & Adhere to Mirrors】This Double Sided silicone suction phone case mount allows you to stick your phone to the mirror easily. No longer holding your phone in one hand to watch video tutorials while making up.
  • 【Strong Grip on the Smooth Surface】You can easily hang your phone anywhere with a smooth surface. All you do is you clean off your phone and smooth surface. It is STURDY and it not only sticks to mirrors, it also sticks to windows, it sticks to refrigerators, tiles and other clean, flat surfaces.
  • 【Press Down Firmly Every 30 Minutes】Use your palm or fingers to press the phone down firmly and check it's secure before letting go. Apply even pressure for a few seconds to allow the suction cup to adhere properly. To maintain the grip and prevent accidental falls, it's a good practice to periodically reapply pressure to the suction cup.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

8. Review code quality and resilience in context

Review the build configuration, dependencies, debug settings, and integrity controls included in the release candidate. Where the threat model calls for it, assess tampering defenses and root or jailbreak detection on the corresponding device state. MASVS includes code-quality and resilience control groups, with MASTG techniques for examining them.

Detection of a rooted or jailbroken device is one control to evaluate, not proof that the app is secure. Record what the app does when a check triggers and whether the behavior matches the stated threat model and user impact.

9. Combine automation with manual verification

Automate stable checks that can be repeated reliably, such as selected configuration checks or regression tests for known security-sensitive flows. Then manually verify high-impact paths, unexpected states, and behaviors that depend on device features or user interaction. OWASP’s checklist can serve as a baseline for manual work or a template for automated tests; neither removes the need to interpret results in the context of the app.

For each result, keep the build identifier, device model and OS, device state, account role, preconditions, exact steps, observed evidence, impact, and MASVS/MASTG mapping. Track outcomes distinctly as passed, failed, not applicable, or not tested. A failed test should describe an observable security issue and its conditions, not merely a tool alert.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

10. Troubleshoot misleading or incomplete results

Symptom Possible cause Next step
A proxy shows no app traffic Pinning, mutual TLS, proxy setup, or another environmental constraint Verify the test configuration and record the visibility limit; do not label the connection secure based only on the absence of captured traffic.
A test cannot find expected local data The workflow did not create it, the wrong account or build was used, or the inspection method cannot access the location Repeat the documented workflow and confirm account, build, and inspection scope before concluding the data is absent.
A backend action succeeds after a UI restriction The restriction may exist only in the client Repeat only against the authorized test backend and verify server-side authorization for the action and role.
Results differ across Android phones OS, manufacturer, or hardware-backed storage differences Compare recorded device and OS details and test the supported configurations relevant to the finding.
An automated check reports a possible issue The check may lack the app-specific context or may not exercise the full workflow Manually reproduce it, document preconditions and impact, and map the verified behavior to the selected control.
A resilience check behaves differently on a modified device The test device state may be outside the normal release condition Keep modified-device observations separate from stock-device results and interpret them under the agreed threat model.

Or skip the browser setup

ScreenshotNeo is a website screenshot API, not a native mobile-app security testing tool. It can capture a browser-accessible test page or web-based report, but it cannot inspect an installed app’s local storage, network security, or platform integrations. For an authorized web page, one GET request can save a screenshot; see the ScreenshotNeo API documentation for parameters.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo can accept cookie or consent banners before capture and remove more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be turned off. Bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and responses identify the page verdict and billing status in headers. Its MCP server provides screenshot, page-info, and PDF tools for AI agents. The free plan includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Those captures are useful for web-visible evidence, not a replacement for testing the app on devices. Learn about ScreenshotNeo, or sign up for 1,000 free screenshots a month with no card.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.