What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
- Current device model and OS version coverage: confirm against vendor docs
- On premises appliance availability and requirements: confirm
- API and CI integration surface: confirm against vendor docs
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Corellium runs unmodified mobile operating systems as virtual machines on Arm server hardware. This is virtualization, not emulation: guest firmware executes natively on Arm cores under a hypervisor, with peripherals modeled well enough that the stock operating system boots and behaves as it does on hardware. For security work that means an iOS or Android device you fully control, without sourcing hardware, waiting for a public jailbreak, or bricking anything.
That control is the product. Virtual devices come with elevated access already available, so you can read and write the filesystem, load unsigned code, and attach to processes without first defeating platform protections. The platform adds its own instrumentation: kernel level debugging, execution tracing of system calls, and capture of all device traffic including traffic from processes you cannot normally proxy. Snapshot and restore matters more than it sounds. You take a device to a precise state, run a destructive experiment, and roll back in seconds, which turns fuzzing and malware detonation into a repeatable loop. Devices are driven through an API, so a lab can be scripted.
Where it fits
This is a research and deep testing environment, not a pipeline scanner. The operators are vulnerability researchers, malware analysts, mobile penetration testers and teams validating that their own app's anti tampering controls survive a capable adversary. It is available hosted and as an on premises deployment for organizations that cannot send binaries outside their network. You need people who already know how to analyze a mobile binary, because the platform hands you access and steps back.
Strengths
- Rooted or jailbroken device access on demand, on current operating system versions, without depending on the exploit release cycle.
- Snapshot, clone and restore make experiments repeatable and parallel.
- Kernel level visibility and full traffic capture reach places on device tooling cannot, since the hypervisor sits below the guest.
Limitations
- Hardware backed behavior is the hard edge. Anything depending on the secure enclave, attestation, DRM or specific radio and sensor hardware may not reproduce, and apps that check for a genuine device can detect the environment.
- Virtual device coverage is selective, so the exact model and operating system combination you need may not be offered.
- A specialist platform aimed at organizations, with a real learning curve, that sits idle unless you have people whose job is this work.
Who it suits
Security research teams, mobile red teams, government and defense analysts, and product teams whose apps are attacked by people holding the device. A team that mainly needs regression scanning on each release is better served by a scanning platform or a rack of physical test devices.
Used Corellium? Recommend it under your own name and title.
Recommend this tool