Skip to main content

A huge security flaw has been discovered in Apple devices that could allow hackers to steal your passwords and data


tim cook



A group of security researchers have discovered an alarming vulnerability in Apple's mobile and desktop operating systems.
In a newly-released paper, the research group explained how they tested a series of attacks that were able to bypass security checks, steal passwords, and even critical app data.
The vulnerability was discovered to exist on Apple devices including the iPhone, iPad, and Mac computers.
Due to the way Apple built apps to communicate with each other, the paper writes, researchers were able to "steal such confidential information as the passwords for iCloud, email and bank, and the secret token of Evernote."
Basically, these researchers were able to build a malware that was uploaded to Apple's App Store in the form of a typical app, which was then able to steal credentials from the existing apps on the researchers' phones. These credentials include passwords and other precious app data that's supposed to be off-limits.
The lead researcher, Luyi Xing, told the Register that his team was able to "gain unauthorized access to other apps' sensitive data such as passwords and tokens from iCloud, Mail app and all web passwords stored by Google Chrome."
According to the Register, Xing and his team informed Apple, which asked for six months to deal with issue. The six months have now passed and the vulnerabilities persist, say the researchers. 
The ramifications of these findings could be huge. Very little has been written about the potential cross-app vulnerabilities in Apple's software, and this discovery shows some huge holes certainly exist.
The researchers tested this type of attack with large sample of Apple apps and found that "more than 88.6%" were completely exposed. These include extremely popular apps like password manager 1Password and Google Chrome.
"The consequences of these attacks are serious," the paper concludes, "including leak of user passwords, secrete tokens and all kinds of sensitive documents."
In short, this vulnerability could quickly become bad news for Apple if hackers or other malicious parties take advantage of the security holes, and there's no way to know if any attacks utilizing this method have already been carried out. For Apple's part, the company needs to figure out a way to patch the vulnerability across both its iOS and Mac OS X operating systems.
Business Insider has reached out to Apple, and we will update the post when we hear back.
You can watch a video showcasing how a malicious app can utilize the vulnerability to steal stored passwords from Google Chrome.

Comments

Popular posts from this blog

What is your preferred smartphone screen size

Screen envy. We all have it. Or do we? See, that’s the thing, I’m just not so sure. One thing I am sure about is that our phone screens have gotten progressively bigger and bigger over the last few years. The funny thing is, we as a society have taken that ball and run with it, like we just don’t care. But I always thought we did care? Some time ago, when phones were in the sub-5” range, we used to have a term called “phablet” which described an almost absurdly big phone. The definition varied from person to person. I always considered a phone with a screen 5.5” or bigger to be a phablet. The Galaxy Note fell into that category. The Lumia 1520 certainly did. There are others as well. I was safely ensconced in the 4.5” area at the time with my Lumia 920. What did I know? Leon’s getting laaaaaaaarrrger But slowly, phones started topping the 5” mark. I’m not talking about phablets here, I’m talking about normal flagship phones – the Galaxy S4 (barely) and the HTC One (M7) are ...

Facebook Now Supports PGP To Send You Encrypted Emails

You can now instruct Facebook to encrypt every email it sends to you so nobody — not even the NSA — is likely to be able to read your messages anytime soon. All you have to do is import your public PGP key into your Facebook settings and you’re good to go. The problem here, of course, is that most people have no idea how public/private key email encryption works and how to even get started with it. In the wake of Edward Snowden’s leaks, a number of organizations, including Google, promised to completely hide the complexities of end-to-end email encryption from regular users. Very few of these products have materialized so far, however — not for lack of trying, but because this is actually a very complex problem, both from a technical and user experience perspective. Facebook uses the well-established PGP scheme (the GNU Privacy Guard implementation of  OpenPGP, to be precise) to encrypt messages and tools lik...

Intel announces the first 14 nanometre processor

At the Computex conference in Taipei, chipmaker Intel has revealed a fanless mobile PC reference design using the first of its next-generation 14nm "Broadwell" processors. The 2 in 1 pictured here is a 12.5" screen that is just 7.2 mm thick with keyboard detached and weighs 670 grams.  The Surface Pro 3  – for comparison – is 9.1 mm thick and weighs 800 grams. It includes a media dock that provides additional cooling for a burst of performance. The next-generation chip is purpose-built for 2 in 1s and will hit the market later in  2014 . Called the Intel Core M, it will be the most energy-efficient Intel Core processor in the company's history with power usage cut by up to 45 percent, resulting in 60 percent less heat. The majority of designs based on this new chip are expected to be fanless, with up to  32 hours of battery life,  offering both a lightning-fast tablet and razor-thin laptop. Intel is also delivering innovation and performance for the ...

How to Choose BitLocker Drive Encryption Method and Cipher Strength in Windows 10?

BitLocker is an encryption method that enables users to lock the different drives in  Windows . The drives which are protected by BitLocker are accessed by passwords. Windows has provided opportunity for users to choose and configure the  cipher  strength and algorithm used by BitLocker Drive Encryption. This can be achieved via the Local Group Policy editor. The Local Policy Editor will let you configure and select the cipher method for BitLocker encryption. By default it is not configured but you can choose your choiceable encryption method by enabling the Policy Setting. If the drive is already encrypted or if encryption is in progress, the encyption method will have no effect. If you leave the policy unconfigured, then BitLocker will use the default encryption method of AES 128-bit with Diffuser or the encryption method specified by the setup script. Steps to Choose BitLocker Drive Encryption Method and Cipher Strength in Windows 10 1.  ...

Laser gun is deployed and operational on U.S. Navy warship

After several years of research and testing, the U.S. Navy has introduced a new laser gun designed to protect ships without using ammunition.   Another entry on our  timeline  is now a reality as the U.S. Navy has authorised the first operational use of a laser weapon. This new hi-tech system – known as the Laser Weapon System (LaWS) – is designed to serve as a form of defence against drones and other small flying vehicles or small-boat enemies including suicide attackers. It is highly accurate, able to hit objects moving at up to 300 mph (480 km/h). The LaWS fires a solid-state infrared beam with two modes: high output to destroy a target, and low output for optical "dazzling", warning shots or to cripple a potential attacker. Among the advantages of this device versus projectile weapons is the low cost per shot, as each firing of the weapon requires only minimal cost for generating the energetic pulse; by contrast ordnance for projectile weapons must be des...