iOS and OS X Security Flaws Enable Malicious Apps to Steal Passwords and Other Data

A team of six researchers from Indiana University, Georgia Tech and Peking University have published an in-depth report exposing a series of security vulnerabilities that enable sandboxed malicious apps, approved on the App Store, to gain unauthorized access to sensitive data stored in other apps, including iCloud passwords and authentication tokens, Google Chrome saved web passwords and more.


The thirteen-page research paper "Unauthorized Cross-App Resource Access on Mac OS X and iOS" details that inter-app interaction services, ranging from the Keychain and WebSocket on OS X to the URL Scheme on OS X and iOS, can be exploited to steal confidential information and passwords, including those stored in popular password vaults such as 1Password by AgileBits.

"We completely cracked the keychain service - used to store passwords and other credentials for different Apple apps - and sandbox containers on OS X, and also identified new weaknesses within the inter-app communication mechanisms on OS X and iOS which can be used to steal confidential data from Evernote, Facebook and other high-profile apps."

The different cross-app and communication mechanism vulnerabilities discovered on iOS and OS X, identified as XARA weaknesses, include Keychain password stealing, IPC interception, scheme hijacking and container cracking. The affected apps and services include iCloud, Gmail, Google Drive, Facebook, Twitter, Chrome, 1Password, Evernote, Pushbullet, Dropbox, Instagram, WhatsApp, Pinterest, Dashlane, AnyDo, Pocket and several others.


Lead researcher Luyi Xing told The Register that he reported the security flaws to Apple in October 2014 and complied with the iPhone maker's request to withhold publishing the information for six months, but has not heard back from the company since and is now exposing the zero-day vulnerabilities to the public. The flaws affect thousands of OS X apps and hundreds of iOS apps and can now be weaponized by attackers.

Popular Stories

iPhone 17 Pro 3 4ths Perspective Aluminum Camera Module 1

iPhone 17 Pro Launching Later This Year With These 12 New Features

Sunday April 13, 2025 7:52 am PDT by
While the iPhone 17 Pro and iPhone 17 Pro Max are not expected to launch until September, there are already plenty of rumors about the devices. Below, we recap key changes rumored for the iPhone 17 Pro models as of April 2025: Aluminum frame: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and iPhone 16 Pro models have a titanium frame, and the iPhone ...
Apple 2025 Thumb 1

10 Products Still Coming From Apple in 2025

Friday April 11, 2025 4:14 pm PDT by
Apple may have updated several iPads and Macs late last year and early this year, but there are still multiple new devices that we're looking forward to seeing in 2025. Most will come in September or October, but there could be a few surprises before then. We've rounded up a list of everything that we're still waiting to see from Apple in 2025. iPhone 17, 17 Air, and 17 Pro - We get...
iOS 18 Siri Personal Context

Report Reveals Internal Chaos Behind Apple's Siri Failure

Thursday April 10, 2025 7:15 am PDT by
A new report from The Information today reveals much of the internal turmoil behind Apple Intelligence's revamped version of Siri. Apple apparently weighed up multiple options for the backend of Apple Intelligence. One initial idea was to build both small and large language models, dubbed "Mini Mouse" and "Mighty Mouse," to run locally on iPhones and in the cloud, respectively. Siri's...
M6 MacBook Pro Feature 1

Waiting for the Perfect MacBook Pro? 2026 Might Be the Year

Thursday April 10, 2025 4:19 am PDT by
Apple in October 2024 overhauled its 14-inch and 16-inch MacBook Pro models, adding M4, M4 Pro, and M4 Max chips, Thunderbolt 5 ports on higher-end models, display changes, and more. That's quite a lot of updates in one go, but if you think this means a further major refresh for the MacBook Pro is now several years away, think again. Bloomberg's Mark Gurman has said he expects only a small...
maxresdefault

The MacRumors Show: New iOS 19, iPhone 17, and Apple Watch Ultra 3 Leaks

Friday April 11, 2025 7:13 am PDT by
On this week's episode of The MacRumors Show, we catch up on the latest iOS 19 and watchOS 12 rumors, upcoming devices, and more. Subscribe to The MacRumors Show YouTube channel for more videos Detailed new renders from leaker Jon Prosser claim to provide the best look yet at the complete redesign rumored to arrive in iOS 19, showing more rounded elements, lighting effects, translucency, and...
iPad Pro iPadOS

iPadOS 19 Will Be 'More Like macOS' in Three Ways

Sunday April 13, 2025 6:43 am PDT by
A common complaint about the iPad Pro is that the iPadOS software platform fails to fully take advantage of the device's powerful hardware. That could soon change. Bloomberg's Mark Gurman today said that iPadOS 19 will be "more like macOS." Gurman said that iPadOS 19 will be "more like a Mac" in three ways:Improved productivity Improved multitasking Improved app window management...
Foldable iPhone 2023 Feature Homescreen

Foldable iPhone Resolutions Leak With Under-Screen Camera Tipped

Monday April 14, 2025 3:12 am PDT by
Apple's upcoming foldable iPhone (or "iPhone Fold") will feature two screens as part of its book-style design, and a Chinese leaker claims to know the resolutions for both of them. According to the Weibo-based account Digital Chat Station, the inner display, which is approximately 7.76 inches, will use a 2,713 x 1,920 resolution and feature "under-screen camera technology." Meanwhile, the...
apple intelligence black

NYT: Apple's AI Struggles Began with 2023 Chip Budget Dispute

Friday April 11, 2025 4:33 am PDT by
Apple's current struggles with Apple Intelligence and Siri began in early 2023 when AI head John Giannandrea sought approval from CEO Tim Cook to purchase more AI chips for development, according to a new report from The New York Times. Cook initially approved doubling the team's chip budget, but CFO Luca Maestri reportedly reduced the increase to less than half that amount, and instead...
Apple Vision Pro with battery Feature Blue Magenta

Vision Pro 2 Rumored to Have Two Key Advantages Over Current Model

Sunday April 13, 2025 7:15 am PDT by
Apple is working on a new version of the Vision Pro with two key advantages over the current model, according to Bloomberg's Mark Gurman. Specifically, in his Power On newsletter today, Gurman said Apple is developing a new headset that is both lighter and less expensive than the current Vision Pro, which starts at $3,499 in the U.S. and weighs up to 1.5 pounds. Gurman said Apple is also...

Top Rated Comments

Westside guy Avatar
128 months ago
I'm a long-time Apple user - and I've near had enough. I have no longer have faith in Apple to protect my data ... Android has had its fair share of problems too, but I just trust the engineers at Google to not let stuff like this happen.
You apparently didn't read this paper because it also mentions similar, significant issues on Android.

Security is hard.
Score: 24 Votes (Like | Disagree)
Craiger Avatar
128 months ago
Umm... "... and can now be weaponized by attackers"?? Because the he has made the knowledge of the existence of flaws public? I hope the exact nature of the flaws has been made known to Apple and hope Apple has an official response to this.
Did you read the entire article? It said Apple was told 6 months ago.
Score: 24 Votes (Like | Disagree)
ViktorEvil Avatar
128 months ago
6 months should be plenty of time to fix this. Not good Apple, not good :(
Score: 18 Votes (Like | Disagree)
Alenore Avatar
128 months ago
OSX is the new Windows ;)
Score: 18 Votes (Like | Disagree)
TheTissot11 Avatar
128 months ago
I don't get why this security flaws reported to Apple always seems to get the cold shoulder. Fix when El Capitan is released?
Because Federighi, though might be a great guy, is busy making funny videos for Keynotes instead of devoting time to iron out bugs and make the OS X secure. Sadly this seems to be true...
Score: 17 Votes (Like | Disagree)
Phil A. Avatar
128 months ago
I'm a long-time Apple user - and I've near had enough. I have no longer have faith in Apple to protect my data. Tim Cook can ramble on about privacy all he wants, but we all know that software has never been Apple's strength. It may look pretty, but vulnerabilities like these are becoming all too common. Android has had its fair share of problems too, but I just trust the engineers at Google to not let stuff like this happen. The last major flaw I recall from Android was that random number generator that wasn't implemented correctly and allowed some bitcoin wallets to be hijacked. That was hardly as widespread as this flaw. It's so frustrating.
Apple should have fixed this issue, but I don't see the point in hyperbole: All systems have vulnerabilities and Google / Samsung / Sony / HTC / Apple are all as bad as each other. There's an article on the same website (the register) today about a flaw in the latest Samsung phones that will allow the installation of malware simply by connecting to a compromised WiFi service so it's not been a good day all round for software!
Score: 16 Votes (Like | Disagree)