Run a professional iOS application assessment from IPA to final report.
Work through a complete black-box assessment of MediVault using a controlled iOS research guest, Burp, Frida, static analysis, runtime instrumentation, storage review, IPC testing, RASP bypass, client-side patching, and reproducible evidence.
Full access includes the intentionally vulnerable MediVault IPA, matching Swift source, and the reusable course script library. Lab packages remain protected by the course entitlement.
Workbench: vPhone, Burp, Frida
Stand up a jailbroken virtual iPhone, SSH into /var/jb, and put Burp and Frida 17 on the wire.
Engagement model and the iOS security stack
Scope the assessment, then read AMFI, signing, and the sandbox from the guest CLI.
Static: the IPA before it runs
Read MediVault as a bundle: entitlements, strings, pins, CoreML, and the attack-surface map.
Network: Burp on a jailbroken iOS 26 device
Proxy at boot, kill pinning two ways, and stay honest about the mock backend.
Runtime: change what the running app believes
Typical iOS functions, then Frida, Objection, and the other runtime tactics a tester uses to exploit them.
Data at rest
Walk the container as mobile and as root. SQLite, keychain, snapshots, file protection.
Authentication and cryptography
Mock login, LAContext vs Keychain ACL, App Attest as an honest negative.
IPC and WebView
uiopen schemes, App Group writes, pasteboard, WKWebView bridges that leak PHI.
RASP and jailbreak detection
Map MediVault detectors, bypass without touching __TEXT, inject with opainject, triage crashes.
Client-side patching
Dump, byte-patch, survive CODE_PAGE_MODIFIED, insert_dylib, embed Frida Gadget.
Evidence, report, capstone
Replayable evidence, CVSS-mobile, the full MediVault finding set, and a delivered report.