Group Purchasing
Group Purchasing

Collaborative Mobile App Security Development and Analysis

Collaborative Mobile App Security Development and Analysis (PDF, 3.50MB)Published: 19 May, 2025
Created by:
Jeroen Beckers
Jeroen Beckers

Collaborative Mobile App Security Development and Analysis, published by SANS Institute in May 2025, is a hands-on product review evaluating how Corellium's virtual device platform addresses common obstacles in mobile application security testing. The review covers testing on both iOS and Android, focusing on the Corellium Viper environment used for security assessments and malware analysis, with additional coverage of the more advanced Corellium Falcon environment for vulnerability research.

Key findings:

  • Corellium virtualizes ARM-based iOS and Android devices through its CHARM (Corellium Hypervisor for ARM) technology, letting testers spin up devices like an iPhone 16 Pro Max running iOS 18.3.1 without needing physical jailbroken hardware
  • Corellium typically adds support for new iOS releases within about two weeks of Apple's official release
  • Frida works out of the box on Corellium's virtual devices, including on iOS 17 and 18, removing the need to repackage applications with a Frida Gadget
  • Virtual devices provide full root filesystem access on iOS 18, something current "rootless" jailbreaks cannot do on physical hardware
  • SSL certificate validation is disabled by default across popular libraries on all supported iOS versions, simplifying setup for network traffic interception
  • Corellium's automated testing tool MATRIX ran 58 tests against the intentionally vulnerable iGoat-Swift application, identifying 8 artifacts and correctly flagging real issues such as a biometric authentication bypass, with only 2 false positives among 17 failed tests
  • Virtual devices can appear as locally connected USB devices through USBFlux, letting standard tools like Frida, Objection, and Xcode work without any setup changes
  • The platform's main limitation is that virtual devices lack the Apple App Store, so testers must source decrypted IPA files separately
  • Cloud-hosted devices introduce some latency compared to physical hardware, though Corellium offers an on-site appliance option for lower latency and data privacy
  • Corellium also supports Android devices, offering ADB access, snapshots, a file browser, and automatic SSL pinning bypasses

The review's overall takeaway is that Corellium doesn't replace manual mobile security analysis, but it removes several of the biggest practical obstacles to it, particularly on iOS. Testing recent iOS versions has traditionally required jailbroken hardware that is hard to obtain and share across a distributed team; Corellium's virtualized approach gives root-level access, tool compatibility, and shareable snapshots without that hardware dependency. The reviewer notes that automated tools like MATRIX can surface likely issues quickly, but reverse engineering complex application logic still requires a human analyst. The review was conducted by a SANS Certified Instructor and Mobile Solution Lead, who tested the Corellium Viper environment directly, including creating and interacting with a virtual iPhone 16 Pro Max on iOS 18.3.1 and validating the MATRIX automated testing tool against the OWASP iGoat-Swift benchmark application.

Collaborative Mobile App Security Development and Analysis

Related Webcast

Mobile app security is more critical—and more complex—than ever. With growing pressure to release quickly, mobile security teams often face tough trade-offs: limited access to devices, remote team coordination challenges, and slow, unreliable emulators that fail to mirror real-world behavior.

Man talking into microphone

FAQ

Meet Your Author

Jeroen Beckers
Jeroen Beckers

Jeroen Beckers

Certified Instructor

Jeroen Beckers is a SANS instructor and Mobile Solution Lead at NVISO, specializing in Android and iOS security.

Read more about Jeroen Beckers