Workflow: SSL Pinning Bypass
Triage
- Try universal Objection bypass first.
- If traffic still fails to decrypt in Burp, identify the pinning library.
- Write/adapt a targeted Frida hook.
Method 1 — Objection Universal
objection -g <bundle_id> explore
> ios sslpinning disableMethod 2 — Frida Universal Script
frida -U -f <bundle_id> -l scripts/ssl_pinning_bypass.js --no-pauseCovers: NSURLSession, SecTrustEvaluate*, AFNetworking AFSecurityPolicy, TrustKit, Alamofire ServerTrustManager.
Method 3 — Identify Custom Pinning
objection -g <bundle_id> explore
> ios hooking search classes Trust
> ios hooking search classes SSL
> ios hooking search classes Pin
> ios hooking search methods pinn
class-dump -H App.app/App -o headers/
grep -RIn -iE 'pin|trust|certificate' headers/ | head -50Then write a targeted hook that overrides the policy's evaluation to return YES / calls the completion handler with NSURLSessionAuthChallengeUseCredential.
Method 4 — ATS Bypass (dev builds only)
Add to Info.plist: NSAppTransportSecurity.NSAllowsArbitraryLoads = YES. Not applicable to installed App Store binaries.
Verification
curl -x http://<burp_host>:8080 --cacert burp.pem https://api.target.tld/health # sanity
# Then drive the app and confirm Burp HTTP history fills with TLS-decrypted traffic.Common Failure Modes
- Pinning happens in a statically linked BoringSSL — hook
SSL_CTX_set_verify/SSL_get_verify_result. - Certificate Transparency enforcement — hook
SecTrustEvaluateWithError. - App uses QUIC/HTTP3 — Burp cannot intercept; force HTTP/2 via proxy or block UDP/443.