Mastering React Native Application Pentesting.
Mobile Security
Cross-platform

Key Takeaways
- How to tell a React Native build from a native one, and what the bridge means for where the application logic actually lives.
- Reverse engineering the JavaScript bundle, including Hermes bytecode, then editing, patching and repackaging the application.
- SSL certificate pinning bypass for React Native, which does not respond to the usual Android techniques.
- Identifying manually installed npm packages inside a shipped app, and a walkthrough of known React Native npm package CVEs.
What's inside
React Native began as a hackathon project and now ships in a large share of cross-platform apps. Pentesting one with a standard Android checklist covers the shell and misses the bundle, and the bundle is where the business logic, the endpoints and the hardcoded secrets tend to sit.
This guide covers the Android side in depth, and most of the techniques carry across to iOS React Native builds. It assumes basic Android pentesting knowledge and some JavaScript, then goes straight to the framework-specific attack surface: the bridge, the bundle, Hermes, pinning and the npm dependency chain.
What the 95 pages cover
Look inside













