iOS and OS X Security Flaws Enable Malicious Apps to Steal Passwords and Other Data

A team of six researchers from Indiana University, Georgia Tech and Peking University have published an in-depth report exposing a series of security vulnerabilities that enable sandboxed malicious apps, approved on the App Store, to gain unauthorized access to sensitive data stored in other apps, including iCloud passwords and authentication tokens, Google Chrome saved web passwords and more.


The thirteen-page research paper "Unauthorized Cross-App Resource Access on Mac OS X and iOS" details that inter-app interaction services, ranging from the Keychain and WebSocket on OS X to the URL Scheme on OS X and iOS, can be exploited to steal confidential information and passwords, including those stored in popular password vaults such as 1Password by AgileBits.

"We completely cracked the keychain service - used to store passwords and other credentials for different Apple apps - and sandbox containers on OS X, and also identified new weaknesses within the inter-app communication mechanisms on OS X and iOS which can be used to steal confidential data from Evernote, Facebook and other high-profile apps."

The different cross-app and communication mechanism vulnerabilities discovered on iOS and OS X, identified as XARA weaknesses, include Keychain password stealing, IPC interception, scheme hijacking and container cracking. The affected apps and services include iCloud, Gmail, Google Drive, Facebook, Twitter, Chrome, 1Password, Evernote, Pushbullet, Dropbox, Instagram, WhatsApp, Pinterest, Dashlane, AnyDo, Pocket and several others.


Lead researcher Luyi Xing told The Register that he reported the security flaws to Apple in October 2014 and complied with the iPhone maker's request to withhold publishing the information for six months, but has not heard back from the company since and is now exposing the zero-day vulnerabilities to the public. The flaws affect thousands of OS X apps and hundreds of iOS apps and can now be weaponized by attackers.

Popular Stories

iPhone 17 Pro Blue Feature Tighter Crop

iPhone 17 Pro Launching in Three Months With These 12 New Features

Saturday June 14, 2025 5:45 pm PDT by
The iPhone 17 Pro and iPhone 17 Pro Max are three months away, and there are plenty of rumors about the devices. Below, we recap key changes rumored for the iPhone 17 Pro models as of June 2025:Aluminum frame: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and iPhone 16 Pro models have a titanium frame, and the iPhone X through iPhone 14 Pro have a...
iPadOS 26 App Windowing

Apple Explains Why iPads Don't Just Run macOS

Friday June 13, 2025 7:46 am PDT by
iPadOS 26 allows iPads to function much more like Macs, with a new app windowing system, a swipe-down menu bar at the top of the screen, and more. However, Apple has stopped short of allowing iPads to run macOS, and it has now explained why. In an interview this week with Swiss tech journalist Rafael Zeier, Apple's software engineering chief Craig Federighi said that iPadOS 26's new Mac-like ...
Logitech Logo Feature

Logitech Announces Two New Accessories for WWDC

Friday June 13, 2025 7:22 am PDT by
Alongside WWDC this week, Logitech announced notable new accessories for the iPad and Apple Vision Pro. The Logitech Muse is a spatially-tracked stylus developed for use with the Apple Vision Pro. Introduced during the WWDC 2025 keynote address, Muse is intended to support the next generation of spatial computing workflows enabled by visionOS 26. The device incorporates six degrees of...
iphone 16 pro models 1

17 Reasons to Wait for the iPhone 17

Thursday June 12, 2025 8:58 am PDT by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models simultaneously, which is why we often get rumored features months ahead of launch. The iPhone 17 series is no different, and we already have a good idea of what to expect from Apple's 2025 smartphone lineup. If you skipped the iPhone...
iOS 26 Feature

Apple Seeds Revised iOS 26 Developer Beta to Fix Battery Issue

Friday June 13, 2025 10:15 am PDT by
Apple today provided developers with a revised version of the first iOS 26 beta for testing purposes. The update is only available for the iPhone 15 and iPhone 16 models, so if you're running iOS 26 on an iPhone 14 or earlier, you won't see the revised beta. Registered developers can download the new beta software through the Settings app on each device. The revised beta addresses an...
Mac Studio Feature

Apple Begins Selling Refurbished Mac Studio With M4 Max and M3 Ultra Chips at a Discount

Thursday June 12, 2025 10:14 am PDT by
Apple today added Mac Studio models with M4 Max and M3 Ultra chips to its online certified refurbished store in the United States, Canada, Japan, Singapore, and many European countries, for the first time since they were released in March. As usual for refurbished Macs, prices are discounted by approximately 15% compared to the equivalent new models on Apple's online store. Note that Apple's ...
m4 macbook air pink

Apple Now Selling Refurbished M4 MacBook Air Models

Friday June 13, 2025 3:34 pm PDT by
Apple today added M4 MacBook Air models to its refurbished store in the United States, making the latest MacBook Air devices available at a discounted price for the first time since they launched earlier this year. Both 13-inch and 15-inch MacBook Air models are available, with Apple offering multiple capacities and configurations. The refurbished devices are discounted by approximately 15...

Top Rated Comments

Westside guy Avatar
131 months ago
I'm a long-time Apple user - and I've near had enough. I have no longer have faith in Apple to protect my data ... Android has had its fair share of problems too, but I just trust the engineers at Google to not let stuff like this happen.
You apparently didn't read this paper because it also mentions similar, significant issues on Android.

Security is hard.
Score: 24 Votes (Like | Disagree)
Craiger Avatar
131 months ago
Umm... "... and can now be weaponized by attackers"?? Because the he has made the knowledge of the existence of flaws public? I hope the exact nature of the flaws has been made known to Apple and hope Apple has an official response to this.
Did you read the entire article? It said Apple was told 6 months ago.
Score: 24 Votes (Like | Disagree)
ViktorEvil Avatar
131 months ago
6 months should be plenty of time to fix this. Not good Apple, not good :(
Score: 18 Votes (Like | Disagree)
Alenore Avatar
131 months ago
OSX is the new Windows ;)
Score: 18 Votes (Like | Disagree)
TheTissot11 Avatar
131 months ago
I don't get why this security flaws reported to Apple always seems to get the cold shoulder. Fix when El Capitan is released?
Because Federighi, though might be a great guy, is busy making funny videos for Keynotes instead of devoting time to iron out bugs and make the OS X secure. Sadly this seems to be true...
Score: 17 Votes (Like | Disagree)
Phil A. Avatar
131 months ago
I'm a long-time Apple user - and I've near had enough. I have no longer have faith in Apple to protect my data. Tim Cook can ramble on about privacy all he wants, but we all know that software has never been Apple's strength. It may look pretty, but vulnerabilities like these are becoming all too common. Android has had its fair share of problems too, but I just trust the engineers at Google to not let stuff like this happen. The last major flaw I recall from Android was that random number generator that wasn't implemented correctly and allowed some bitcoin wallets to be hijacked. That was hardly as widespread as this flaw. It's so frustrating.
Apple should have fixed this issue, but I don't see the point in hyperbole: All systems have vulnerabilities and Google / Samsung / Sony / HTC / Apple are all as bad as each other. There's an article on the same website (the register) today about a flaw in the latest Samsung phones that will allow the installation of malware simply by connecting to a compromised WiFi service so it's not been a good day all round for software!
Score: 16 Votes (Like | Disagree)