iOS and OS X Security Flaws Enable Malicious Apps to Steal Passwords and Other Data

A team of six researchers from Indiana University, Georgia Tech and Peking University have published an in-depth report exposing a series of security vulnerabilities that enable sandboxed malicious apps, approved on the App Store, to gain unauthorized access to sensitive data stored in other apps, including iCloud passwords and authentication tokens, Google Chrome saved web passwords and more.


The thirteen-page research paper "Unauthorized Cross-App Resource Access on Mac OS X and iOS" details that inter-app interaction services, ranging from the Keychain and WebSocket on OS X to the URL Scheme on OS X and iOS, can be exploited to steal confidential information and passwords, including those stored in popular password vaults such as 1Password by AgileBits.

"We completely cracked the keychain service - used to store passwords and other credentials for different Apple apps - and sandbox containers on OS X, and also identified new weaknesses within the inter-app communication mechanisms on OS X and iOS which can be used to steal confidential data from Evernote, Facebook and other high-profile apps."

The different cross-app and communication mechanism vulnerabilities discovered on iOS and OS X, identified as XARA weaknesses, include Keychain password stealing, IPC interception, scheme hijacking and container cracking. The affected apps and services include iCloud, Gmail, Google Drive, Facebook, Twitter, Chrome, 1Password, Evernote, Pushbullet, Dropbox, Instagram, WhatsApp, Pinterest, Dashlane, AnyDo, Pocket and several others.


Lead researcher Luyi Xing told The Register that he reported the security flaws to Apple in October 2014 and complied with the iPhone maker's request to withhold publishing the information for six months, but has not heard back from the company since and is now exposing the zero-day vulnerabilities to the public. The flaws affect thousands of OS X apps and hundreds of iOS apps and can now be weaponized by attackers.

Top Rated Comments

Westside guy Avatar
116 months ago
I'm a long-time Apple user - and I've near had enough. I have no longer have faith in Apple to protect my data ... Android has had its fair share of problems too, but I just trust the engineers at Google to not let stuff like this happen.
You apparently didn't read this paper because it also mentions similar, significant issues on Android.

Security is hard.
Score: 24 Votes (Like | Disagree)
Craiger Avatar
116 months ago
Umm... "... and can now be weaponized by attackers"?? Because the he has made the knowledge of the existence of flaws public? I hope the exact nature of the flaws has been made known to Apple and hope Apple has an official response to this.
Did you read the entire article? It said Apple was told 6 months ago.
Score: 24 Votes (Like | Disagree)
ViktorEvil Avatar
116 months ago
6 months should be plenty of time to fix this. Not good Apple, not good :(
Score: 18 Votes (Like | Disagree)
Alenore Avatar
116 months ago
OSX is the new Windows ;)
Score: 18 Votes (Like | Disagree)
TheTissot11 Avatar
116 months ago
I don't get why this security flaws reported to Apple always seems to get the cold shoulder. Fix when El Capitan is released?
Because Federighi, though might be a great guy, is busy making funny videos for Keynotes instead of devoting time to iron out bugs and make the OS X secure. Sadly this seems to be true...
Score: 17 Votes (Like | Disagree)
Phil A. Avatar
116 months ago
I'm a long-time Apple user - and I've near had enough. I have no longer have faith in Apple to protect my data. Tim Cook can ramble on about privacy all he wants, but we all know that software has never been Apple's strength. It may look pretty, but vulnerabilities like these are becoming all too common. Android has had its fair share of problems too, but I just trust the engineers at Google to not let stuff like this happen. The last major flaw I recall from Android was that random number generator that wasn't implemented correctly and allowed some bitcoin wallets to be hijacked. That was hardly as widespread as this flaw. It's so frustrating.
Apple should have fixed this issue, but I don't see the point in hyperbole: All systems have vulnerabilities and Google / Samsung / Sony / HTC / Apple are all as bad as each other. There's an article on the same website (the register) today about a flaw in the latest Samsung phones that will allow the installation of malware simply by connecting to a compromised WiFi service so it's not been a good day all round for software!
Score: 16 Votes (Like | Disagree)

Popular Stories

Apple Silicon AI Optimized Feature Siri

Apple Releases Open Source AI Models That Run On-Device

Wednesday April 24, 2024 3:39 pm PDT by
Apple today released several open source large language models (LLMs) that are designed to run on-device rather than through cloud servers. Called OpenELM (Open-source Efficient Language Models), the LLMs are available on the Hugging Face Hub, a community for sharing AI code. As outlined in a white paper [PDF], there are eight total OpenELM models, four of which were pre-trained using the...
iOS 18 Siri Integrated Feature

iOS 18 Rumored to Add These 10 New Features to Your iPhone

Wednesday April 24, 2024 2:05 pm PDT by
Apple is set to unveil iOS 18 during its WWDC keynote on June 10, so the software update is a little over six weeks away from being announced. Below, we recap rumored features and changes planned for the iPhone with iOS 18. iOS 18 will reportedly be the "biggest" update in the iPhone's history, with new ChatGPT-inspired generative AI features, a more customizable Home Screen, and much more....
maxresdefault

Apple Announces 'Let Loose' Event on May 7 Amid Rumors of New iPads

Tuesday April 23, 2024 7:11 am PDT by
Apple has announced it will be holding a special event on Tuesday, May 7 at 7 a.m. Pacific Time (10 a.m. Eastern Time), with a live stream to be available on Apple.com and on YouTube as usual. The event invitation has a tagline of "Let Loose" and shows an artistic render of an Apple Pencil, suggesting that iPads will be a focus of the event. Subscribe to the MacRumors YouTube channel for more ...
Apple Vision Pro Dual Loop Band Orange Feature 2

Apple Cuts Vision Pro Shipments as Demand Falls 'Sharply Beyond Expectations'

Tuesday April 23, 2024 9:44 am PDT by
Apple has dropped the number of Vision Pro units that it plans to ship in 2024, going from an expected 700 to 800k units to just 400k to 450k units, according to Apple analyst Ming-Chi Kuo. Orders have been scaled back before the Vision Pro has launched in markets outside of the United States, which Kuo says is a sign that demand in the U.S. has "fallen sharply beyond expectations." As a...
iPad And Calculator App Feature 1

Apple Finally Plans to Release a Calculator App for iPad Later This Year

Tuesday April 23, 2024 9:08 am PDT by
Apple is finally planning a Calculator app for the iPad, over 14 years after launching the device, according to a source familiar with the matter. iPadOS 18 will include a built-in Calculator app for all iPad models that are compatible with the software update, which is expected to be unveiled during the opening keynote of Apple's annual developers conference WWDC on June 10. AppleInsider...
macbook pro purple february

Best Buy Introduces Record Low Prices on Apple's M3 MacBook Pro for Members

Thursday April 25, 2024 7:41 am PDT by
Best Buy is discounting a collection of M3 MacBook Pro computers today, this time focusing on the 14-inch version of the laptop. Every deal in this sale requires you to have a My Best Buy Plus or Total membership, although non-members can still get solid second-best prices on these MacBook Pro models. Note: MacRumors is an affiliate partner with Best Buy. When you click a link and make a...