This technical report presents the findings from a penetration test and source code audit conducted on the Tor VPN for Android and the Tunnel Interface for Arti. The assessment, requested by The Tor Project, took place over a two-week period in summer 2025 and involved a team of six security specialists. The testing identified a total of eighteen findings, with four classified as exploitable vulnerabilities and the remaining fourteen as best practice suggestions. Key areas of concern included absent input data validations and vulnerabilities related to DNS resolver and Denial-of-Service attack vectors. The report outlines the scope of the testing, the methodology employed, and provides a chronological list of identified vulnerabilities along with technical descriptions and recommendations for remediation. The findings indicate that while the core integration of Tor is robust, specific enhancements and modifications are necessary to strengthen the overall security posture of the applications assessed.