What You Need to Know About Recent 'XARA' Exploits Against iOS and OS X - MacRumors
Skip to Content

What You Need to Know About Recent 'XARA' Exploits Against iOS and OS X

Earlier this week, researchers from several universities published a report exposing a string of security vulnerabilities in iOS and OS X. The vulnerabilities, all labeled as XARA weaknesses, let malicious apps approved on the Mac and iOS App Stores gain access to sensitive data like passwords.

The report details several methods that inter-app interaction services can use to access everything from the Keychain and Websocket on OS X to the URL scheme on iOS and OS X, giving hackers access to sensitive data, including information stored within third-party apps like 1Password, Gmail, Facebook, Twitter, Instagram, Evernote, and more.


Following the release of the report, iMore's Nick Arnott and Rene Ritchie have taken an in-depth look at the XARA weaknesses in a series of posts on the subject, explaining exactly what they do, how they work on iOS and OS X, and the steps that you can take to protect yourself.

The first post from iMore gives a quick overview of what XARA is, explaining that it's a group of exploits that use malicious apps to gain access to secure information by inserting themselves into the middle of a communications chain or sandbox.

OS X, not iOS, is primarily affected by XARA exploits, and the malicious apps are able to be distributed through the Mac App Store and the iOS Store. After being downloaded, an app using XARA exploits waits to intercept data. Ritchie explains how it works:

For OS X Keychains, it includes pre-registering or deleting and re-registering items. For WebSockets, it includes preemptively claiming a port. For Bundle IDs, it includes getting malicious sub-targets added to the access control lists (ACL) of legitimate apps.

For iOS, it includes hijacking the URL scheme of a legitimate app.

iMore's second in-depth XARA post, written by Nick Arnott, goes into even more detail on the XARA weaknesses and details how to determine if you've been affected. On OS X, checking for malicious keychain entries is possible by opening the Keychain Access app, clicking on an item in the list, choosing "Get Info" and looking at the "Access Control" tab to see which apps have access to the Keychain item.

As detailed by Arnott, the only XARA exploit that affects iOS devices is the one that involves URL scheme hijacking, detectable by paying careful attention to apps that open via URL scheme, as they may look slightly different than the real thing.

All that said, you can help protect yourself from URL scheme hijacking if you're paying attention: When URL schemes are called, the responding application gets called to the foreground. This means that even if a malicious app intercepts the URL scheme intended for another app, it will have to come to the foreground to respond. As such, an attacker will have to do a bit of work to pull of this sort of attack without being noticed by the user.

In one of the videos provided by the researchers, their malicious app attempts to impersonate Facebook. Similar to a phishing website that doesn't look quite like the real thing, the interface presented in the video as Facebook may give some users pause: The app presented isn't logged in to Facebook, and its UI is that of a web view, not the native app.

Apple's known about XARA for several months, and according to the researchers who shared the vulnerability with Apple, the company does appear to have tried to fix it several times without success. Avoiding the exploit is relatively simple, as Ritchie and Arnott point out. Avoiding malicious apps can be done by downloading software only from trusted developers and avoiding anything that seems suspicious.

For those interested in learning more about the XARA weaknesses, iMore's overview post on the exploit and the site's more in-depth post are well worth a read.

Update: Apple on Friday provided iMore with the following statement regarding the XARA exploits:

Earlier this week we implemented a server-side app security update that secures app data and blocks apps with sandbox configuration issues from the Mac App Store," an Apple spokesperson told iMore. "We have additional fixes in progress and are working with the researchers to investigate the claims in their paper."

Tag: iMore

Popular Stories

iphone 17 pro max battery 1 year

Three Years of 80% Charge Limits on iPhone: The Results

Tuesday October 6, 2026 12:59 pm PDT by
Since 2023, Apple's newer iPhones have had an 80 percent charge limit for those who want to extend battery lifespan. Charging to 80 percent instead of 100 percent is supposed to put less stress on the battery, improving longevity. For the last three years, I've used that setting on my iPhone. I started with the iPhone 15 Pro Max, then did the iPhone 16 Pro Max, and most recently, the iPhone...
apple welcome home event

Apple Product Launch Announced for October 13: 'Welcome Home'

Thursday October 8, 2026 9:04 am PDT by
Apple today announced an upcoming product launch that will take place on Tuesday, October 13. We are expecting Apple's announcement to focus on new smart home products, including the long-rumored smart home hub, a new Apple TV 4K, and a refreshed HomePod mini. Subscribe to the MacRumors YouTube channel for more videos. The home hub is an all-new device that's like a cross between an iPad and...
Black Apple Event Logo

Sources: Apple Planning Two Sets of Product Launches in October

Monday October 5, 2026 7:24 pm PDT by
Bloomberg's Mark Gurman recently reported that Apple plans to unveil an all-new home hub, a new HomePod mini, and a new Apple TV 4K on Tuesday, October 13, and MacRumors has since learned about another launch slated for later in the month. Apple is planning to unveil additional new products in the final week of October, according to multiple sources familiar with the matter. While we do...

Top Rated Comments

148 months ago
By the time I enter my password on Chrome, my battery has run out
Score: 25 Votes (Like | Disagree)
Saucesome2000 Avatar
148 months ago
"Avoiding malicious apps can be done by downloading software only from trusted developers and avoiding anything that seems suspicious."

Isn't the point and advantage of the Mac App Store supposed to be that the developer's are vetted and trusted as are the apps? How exactly do we know who trusted developers are? Does Apple plan on having a blue checkmark system?

As an Apple fanboy, this should be their number one priority. Security is one of the top features of Apple products over the competition.
Score: 23 Votes (Like | Disagree)
sniffies Avatar
148 months ago
Never shopping at Zara again.
Score: 12 Votes (Like | Disagree)
148 months ago
I think what troubles me more is the complete silence on Apple's part.
What would you like them to do? Put an ad in the paper?
That kind of stuff needs to be resolved quietly BECAUSE there is no need to broadcast to the hackers.

Also, the people who keep saying that as a fact Apple has done nothing need to read the line where it says they tried (so far unsuccessfully)
Looks like it's not that easy as a poster saying: Just fix it. Flip a switch and we are done!
Score: 9 Votes (Like | Disagree)
148 months ago
I think what troubles me more is the complete silence on Apple's part. This has the potential to be a very serious issue and yet you hear nothing about it from your manufacturer. There is a point where Apple really starts to piss me off with this behaviour. You can see that even the developers of AgileBits are pretty much helpless and can't do anything to fix the problem, while their customers expect a secure product. I wonder how other developers of security software look at this.
Score: 9 Votes (Like | Disagree)
Quu Avatar
148 months ago
So, using 1password - which I heartily recommend to both Mac (& PC!) users is a risk in and of itself!? Now what? Really, Apple, I'm at a loss! I have a boatload of passwords I'm using in my "vault". Fortunately, I just clean installed El Cap on both my Macs. I guess I just shouldn't install anything? Lol. What to do... thoughts...?
This attack would merely allow a program to talk to the 1Password helper app. Essentially, spoofing the browser extension.

This means it will only be able to intercept information you're committing to your password vault or retrieving from your password vault. It will not compromise your entire vault or all of your passwords stored in there.

You would also need to have first installed a malicious application. Your chances of having this vulnerability exploited are microscopic.
Score: 7 Votes (Like | Disagree)
Latest Stories
Apple Reportedly Cuts iPhone 18 Pro Orders After Price Hike Dampens Demand
Apple Reportedly Cuts iPhone 18 Pro Orders After Price Hike Dampens Demand
29 minutes ago
Apple Signs Hiring and Licensing Deal With AI Podcast Startup Huxe
Apple Signs Hiring and Licensing Deal With AI Podcast Startup Huxe
4 hours ago
Apple's October 13 Launch: What's Coming
Apple's October 13 Launch: What's Coming
14 hours ago
Anthropic Says Users Can't Be Needlessly Cruel to Claude
Anthropic Says Users Can't Be Needlessly Cruel to Claude
15 hours ago
Apple to Launch Touchscreen OLED MacBook Pro and OLED iPad mini on October 27
Apple to Launch Touchscreen OLED MacBook Pro and OLED iPad mini on October 27
16 hours ago
Apple Now Pushing iPhone Users Still on iOS 26 to Install iOS 27
Apple Now Pushing iPhone Users Still on iOS 26 to Install iOS 27
17 hours ago
Apple Has a New M&A Chief as Ternus Reshuffles Leadership
Apple Has a New M&A Chief as Ternus Reshuffles Leadership
18 hours ago
Prepare for Apple's New Home Hub With These HomeKit Accessory Deals
Prepare for Apple's New Home Hub With These HomeKit Accessory Deals
19 hours ago
Tim Cook Says He's 'Not Meddling' With Apple's New CEO John Ternus
Tim Cook Says He's 'Not Meddling' With Apple's New CEO John Ternus
19 hours ago
Tim Cook Explains Why He Stepped Down as Apple CEO Before iPhone Duo Launch
Tim Cook Explains Why He Stepped Down as Apple CEO Before iPhone Duo Launch
19 hours ago
Apple Product Launch Announced for October 13: 'Welcome Home'
Apple Product Launch Announced for October 13: 'Welcome Home'
21 hours ago
Amazon Unveils New iPad Rivals With Alexa+ and Google Play
Amazon Unveils New iPad Rivals With Alexa+ and Google Play
22 hours ago
Missed Prime Day? You Can Still Score Big on Apple Devices Today
Missed Prime Day? You Can Still Score Big on Apple Devices Today
22 hours ago
Apple's Cheapest 16-Inch MacBook Pro Just Got a Massive $563 Discount on Amazon
Apple's Cheapest 16-Inch MacBook Pro Just Got a Massive $563 Discount on Amazon
23 hours ago
Apple Still Expected to Announce Three New Products on October 13
Apple Still Expected to Announce Three New Products on October 13
23 hours ago
Leaker Jon Prosser Pushes Back as Apple Seeks His YouTube Data
Leaker Jon Prosser Pushes Back as Apple Seeks His YouTube Data
1 day ago
iPhone Air 2 Could Be as Thin as an Unfolded iPhone Duo
iPhone Air 2 Could Be as Thin as an Unfolded iPhone Duo
1 day ago
New iPad Mini Rumored to Have 60Hz OLED Display Ahead of Launch
New iPad Mini Rumored to Have 60Hz OLED Display Ahead of Launch
5 hours ago
Gurman: OLED MacBook Pro Won't Be 'Significantly Thinner'
Gurman: OLED MacBook Pro Won't Be 'Significantly Thinner'
4 hours ago
Microsoft Launches $2,599 Surface Laptop Ultra to Take on MacBook Pro
Microsoft Launches $2,599 Surface Laptop Ultra to Take on MacBook Pro
2 days ago
Google's SynthID AI Detector is Now Available to Everyone
Google's SynthID AI Detector is Now Available to Everyone
2 days ago
ChatGPT Gets GPT-6 and New Intelligent UI With Visual Answers
ChatGPT Gets GPT-6 and New Intelligent UI With Visual Answers
2 days ago
Get AirPods Pro 3 for $179, Apple Watch for $199, and More Before Prime Day Ends Today
Get AirPods Pro 3 for $179, Apple Watch for $199, and More Before Prime Day Ends Today
2 days ago
Apple Watch Series 12 and Ultra 4 Score 4/10 for Repairability
Apple Watch Series 12 and Ultra 4 Score 4/10 for Repairability
2 days ago
Apple Launches Creative Labs Program With The King's Trust
Apple Launches Creative Labs Program With The King's Trust
2 days ago
Apple Watch Series 12, Ultra 4 Owners Report Skin Irritation
Apple Watch Series 12, Ultra 4 Owners Report Skin Irritation
2 days ago
Boston's MBTA Testing New Charlie Card With Apple Wallet Support
Boston's MBTA Testing New Charlie Card With Apple Wallet Support
2 days ago
Manchester's Bee Card Now Fully Supported in Apple Wallet
Manchester's Bee Card Now Fully Supported in Apple Wallet
2 days ago
You Can Get Up to $149 Off Every New Mac Mini During Prime Day
You Can Get Up to $149 Off Every New Mac Mini During Prime Day
2 days ago
Best Buy Takes $260 Off All iPhone Air Models During Techtober Sale
Best Buy Takes $260 Off All iPhone Air Models During Techtober Sale
2 days ago