An intentionally insecure Android app for practicing mobile VAPT. Demonstrates common Android vulnerabilities like insecure SharedPreferences, exported components, WebView JS bridges, client-side auth bypass, hardcoded secrets, and SSL pinning bypass using Frida.
mobile owasp android-security mobile-security frida root-checker vulnerable-android-apps android-pentesting ssl-bypass android-vapt owasp-vapt-mobile
-
Updated
Dec 13, 2025