Mobile CTF

Outsmart the App. Own the Leaderboard.

[No Phone Required]
[DATE] October 6, 2026
[LOCATION] Metro Building, 1 Butterwick, 6th Floor, Hammersmith, W6 8DL

Join a hands-on mobile Capture the Flag (CTF) event powered by Corellium. Work in controlled iOS and Android environments, investigate realistic mobile risks, and compete for the leaderboard.

Whether you are new to mobile security or already have hands-on experience, the event gives you a practical way to build skills across application testing, runtime analysis, data protection, and API security.

A pentest, gamified.

23
Practical Challenges
4
Skill Domains
2
Platforms: iOS & Android
0
Physical Devices Required

WHAT IS THIS?

Not Just Any CTF

The Corellium Mobile CTF puts you inside an app environment designed by experienced practitioners and built around realistic security scenarios. Your objective is to vulnerabilities, validate the risk and “capture the flag.” Each challenge reflects techniques used in mobile application testing, security research, incident analysis and vulnerability testing.

Launch your mobile device

Access a dedicated iOS or Android device directly from your browser. Each environment is preconfigured for the competition, with no physical phone, jailbreaking, device shipping or shared lab required.

Find the vulnerabilities

Inspect network traffic, analyse the application, instrument runtime behaviour, review local storage and test how security controls respond during execution. Each challenge gives you a practical way to investigate and validate mobile risk.

Capture the flag

Each vulnerability, when exploited correctly, reveals a flag in the format flag{…}. Submit it to the scoreboard, climb the leaderboard, win prizes.

Four Categories. One complete pentest.

Challenges span the full OWASP Mobile Top 10. Whether you’re new to mobile security or a seasoned practitioner, there’s ground to cover in every category.

Do you have what it takes?
Find real vulnerabilities, race against the clock and climb the leaderboard.

Frequently Asked Questions

No. The entire CTF runs on the Corellium Mobile Security Platform that you can access from your browser.  For this event, each participant receives a controlled iOS or Android environment where they can inspect files, observe runtime behavior, analyze network traffic and investigate vulnerabilities without relying on a physical device. 

Yes. The beginner challenges are designed for developers, web security practitioners and anyone interested in learning mobile security.  

Experience with Burp Suite, API testing, or application debugging will give you a useful starting point, but you do not need previous iOS or Android security experience to participate.  

Corellium is a mobile security platform that gives teams access to virtual iOS, iPadOS, and Android environments for testing, research, investigating, training, and reproducible analysis.  

Yes. Bring Burp Suite, Frida, Objection, Ghidra, Python – anything you’d use on a real engagement. The virtual device accepts USB-over-network connections, so your local Frida client can attach just like a physical device. 

Check the event rules – some events allow teams, others are solo. Either way, each participant gets their own virtual device instance so there’s no shared state between players. 

Organizers are available throughout the event. Some challenges have tiered hints available at a point penalty. Post-event writeups are published for all challenges so you can learn what you missed. 

Prizes vary by event and are announced at the start of each competition. Check the specific event listing or ask an organizer at registration for the current prize structure.