iOS and OS X Security Flaws Enable Malicious Apps to Steal Passwords and Other Data

A team of six researchers from Indiana University, Georgia Tech and Peking University have published an in-depth report exposing a series of security vulnerabilities that enable sandboxed malicious apps, approved on the App Store, to gain unauthorized access to sensitive data stored in other apps, including iCloud passwords and authentication tokens, Google Chrome saved web passwords and more.


The thirteen-page research paper "Unauthorized Cross-App Resource Access on Mac OS X and iOS" details that inter-app interaction services, ranging from the Keychain and WebSocket on OS X to the URL Scheme on OS X and iOS, can be exploited to steal confidential information and passwords, including those stored in popular password vaults such as 1Password by AgileBits.

"We completely cracked the keychain service - used to store passwords and other credentials for different Apple apps - and sandbox containers on OS X, and also identified new weaknesses within the inter-app communication mechanisms on OS X and iOS which can be used to steal confidential data from Evernote, Facebook and other high-profile apps."

The different cross-app and communication mechanism vulnerabilities discovered on iOS and OS X, identified as XARA weaknesses, include Keychain password stealing, IPC interception, scheme hijacking and container cracking. The affected apps and services include iCloud, Gmail, Google Drive, Facebook, Twitter, Chrome, 1Password, Evernote, Pushbullet, Dropbox, Instagram, WhatsApp, Pinterest, Dashlane, AnyDo, Pocket and several others.


Lead researcher Luyi Xing told The Register that he reported the security flaws to Apple in October 2014 and complied with the iPhone maker's request to withhold publishing the information for six months, but has not heard back from the company since and is now exposing the zero-day vulnerabilities to the public. The flaws affect thousands of OS X apps and hundreds of iOS apps and can now be weaponized by attackers.

Top Rated Comments

(View all)
Avatar
66 months ago

I'm a long-time Apple user - and I've near had enough. I have no longer have faith in Apple to protect my data ... Android has had its fair share of problems too, but I just trust the engineers at Google to not let stuff like this happen.

You apparently didn't read this paper because it also mentions similar, significant issues on Android.

Security is hard.
Score: 24 Votes (Like | Disagree)
Avatar
66 months ago

Umm... "... and can now be weaponized by attackers"?? Because the he has made the knowledge of the existence of flaws public? I hope the exact nature of the flaws has been made known to Apple and hope Apple has an official response to this.

Did you read the entire article? It said Apple was told 6 months ago.
Score: 24 Votes (Like | Disagree)
Avatar
66 months ago
6 months should be plenty of time to fix this. Not good Apple, not good :(
Score: 18 Votes (Like | Disagree)
Avatar
66 months ago
OSX is the new Windows ;)
Score: 18 Votes (Like | Disagree)
Avatar
66 months ago

I don't get why this security flaws reported to Apple always seems to get the cold shoulder. Fix when El Capitan is released?

Because Federighi, though might be a great guy, is busy making funny videos for Keynotes instead of devoting time to iron out bugs and make the OS X secure. Sadly this seems to be true...
Score: 17 Votes (Like | Disagree)
Avatar
66 months ago

I'm a long-time Apple user - and I've near had enough. I have no longer have faith in Apple to protect my data. Tim Cook can ramble on about privacy all he wants, but we all know that software has never been Apple's strength. It may look pretty, but vulnerabilities like these are becoming all too common. Android has had its fair share of problems too, but I just trust the engineers at Google to not let stuff like this happen. The last major flaw I recall from Android was that random number generator that wasn't implemented correctly and allowed some bitcoin wallets to be hijacked. That was hardly as widespread as this flaw. It's so frustrating.

Apple should have fixed this issue, but I don't see the point in hyperbole: All systems have vulnerabilities and Google / Samsung / Sony / HTC / Apple are all as bad as each other. There's an article on the same website (the register) today about a flaw in the latest Samsung phones that will allow the installation of malware simply by connecting to a compromised WiFi service so it's not been a good day all round for software!
Score: 16 Votes (Like | Disagree)

Top Stories

Apple Warns Against Closing MacBooks With a Cover Over the Camera

Friday July 10, 2020 11:12 am PDT by
Apple this month published a support document that warns customers against closing their Mac notebooks with a cover over the camera as it can lead to display damage. Image via Reddit Apple says that the clearance between the display and the keyboard is designed to very tight tolerances, which can be problematic. Covering the camera can also cause issues with automatic brightness and True Tone....

Leaker: 'iPhone 12 Pro' to Come With 6GB of RAM

Friday July 10, 2020 1:59 am PDT by
Later this year, Apple is expected to release four OLED iPhones in three display sizes, including 5.4, 6.7, and two 6.1-inch models. Rumors suggest the 6.7-inch iPhone and one 6.1-inch model will be higher-end devices, and now leaker @L0vetodream has corroborated previous rumors about the internal specs of Apple's upcoming lineup. Rumors suggest Apple will use 5-nanometer A14 chips in its...

Apple Moving Forward on Semitransparent Lenses for Upcoming AR Headset

Friday July 10, 2020 7:24 am PDT by
Apple and Foxconn have reached a key milestone in the development of Apple's long-rumored augmented reality headset, with the semitransparent lenses for the device moving from prototype to trial production, reports The Information. Apple is developing the lenses on a single production line at a Foxconn factory in Chengdu in southwestern China, where most of Apple’s iPad production is...

Kuo: Apple Silicon Macs to Include 13-inch MacBook Pro and MacBook Air This Year, 14.1-inch and 16-inch MacBook Pro Models Next Year

Friday July 10, 2020 2:58 am PDT by
At last month's WWDC, Apple officially announced that its Mac computers will be transitioned from Intel x86 to homegrown Apple Silicon chips. Apple said it plans to deliver the first Apple Silicon Mac by the end of the year and complete the transition in about two years. According to Apple analyst Ming-Chi Kuo, a 13.3-inch MacBook Pro with a form factor similar to the current 13.3-inch...

Arm-Intel-PowerPC Universal Binaries Are Possible

Saturday July 11, 2020 1:42 pm PDT by
Casual MacRumors visitors may not realize that we have a very active PowerPC forum where users discuss issues related to PowerPC Macs that have not been produced since 2006. Threads range from hardware upgrades and software options to nostalgia: Photo by AphoticD Apple's recently announced transition to Apple Silicon (Arm) based Macs raised some interesting questions about future support...

iPhone 12 Sizes Compared with iPhone SE, 7, 8, SE 2, X, 11, 11 Pro and 11 Pro Max [Update]

Tuesday July 7, 2020 6:49 pm PDT by
Apple is planning on launching the iPhone 12 this fall which is rumored to be coming in 3 different sizes: 5.4", 6.1" and 6.7". The middle size (6.1") matches up with the currently shipping iPhone 11, but the other two sizes will be entirely new. Over the weekend, there was some excitement about how well the new 5.4" iPhone 12 compares to the original iPhone SE. Those who have been hoping...

Tom Hanks WWII Movie 'Greyhound' Debuts on Apple TV+

Friday July 10, 2020 3:33 am PDT by
Apple TV+ today debuted "Greyhound," the highly anticipated Second World War movie starring Tom Hanks as a naval officer given command of Navy destroyer Greyhound in the Battle of the Atlantic. "Greyhound" features Hanks as George Krause, who must fight his own self doubts and personal demons as he leads a convoy of Allied ships against German U-boats to prove that he belongs in command. ...

Top Stories: iOS 14 Public Beta, iPhone 12 Size Comparison, 14-Inch MacBook Pro Rumors

Saturday July 11, 2020 6:00 am PDT by
After one round of developer beta testing, Apple unleashed iOS and iPadOS 14 to a wider audience this week, opening it up to members of the public beta program. There are lots of changes and new features to check out, but as with any beta, be careful about installing it on your main devices. Subscribe to the MacRumors YouTube channel for more videos. Other major stories this week included our ...

Hands-On With tvOS 14: Picture in Picture, 4K YouTube, HomeKit and More

Thursday July 9, 2020 12:48 pm PDT by
Apple at WWDC introduced a new version of tvOS, the software that's designed to run on the fourth and fifth-generation Apple TV models. tvOS updates are often more minor in scale than iOS, watchOS, and macOS updates, but tvOS 14 has some useful new features. Subscribe to the MacRumors YouTube channel for more videos. Apple in tvOS 13 introduced a Picture in Picture option for the Apple TV...

Apple CEO Tim Cook's 2019 Compensation Totaled Over $133 Million

Friday July 10, 2020 12:01 pm PDT by
Apple CEO Tim Cook was the second highest paid CEO in the United States in 2019, according to Bloomberg's list of the highest paid CEOs and executives in 2019. Cook received compensation totaling $133,727,869 by Bloomberg's count. Almost all of Cook's compensation was provided in the form of stock awards and related performance bonuses. As reported by the SEC earlier this year, Cook received ...