A shipped mobile app that was a credential vault
The challenge
An enterprise SaaS vendor needed its cross-platform hybrid CRM client — shipped to customers who hold live customer records — validated across Android, iOS and Windows.
How it unfolded
- Treated the shipped app as an archive, not a program — unpacked and read the binary.
- Found hardcoded backend credentials compiled into the bundle.
- Confirmed (read-only) they granted a live, authenticated session to an internal customer-data API.
- Recovered the at-rest database key from device-derivable material (weak, unsalted key derivation).
- Decrypted the offline data store; bypassed jailbreak detection with a single runtime hook.
- Showed an MDM default silently disabled TLS pinning — enabling full session interception.
Impact
A motivated attacker with nothing but the public app could reach a live customer-data API and decrypt the offline store — on all three platforms.
Outcome
One Critical and five High issues with end-to-end runtime proof, a prioritised “rotate now” credential list, and concrete key-derivation, pinning and token-handling fixes. Testing stopped at proof — no customer records were exfiltrated.