Research on iOS apps shows widespread exposure of secrets


Researchers found that most of the apps available on Apple’s App Store leak at least one hard-coded secret.

The researchers looked at 156,000 iOS apps and discovered more than 815,000 hardcoded secrets, including very sensitive secrets like keys to cloud storage, various Application Programming Interfaces (APIs), and even payment processors. The researchers noted how: “The average app’s code exposes 5.2 secrets, and 71% of apps leak at least one secret.” Secrets hard-coded in the source code of the apps are considered exposed because they are relatively easy to find and abuse by cybercriminals.

Read more…
Source: Malwarebytes Labs


Sign up for our Newsletter


Related:

  • Taiwan prosecutors investigating alleged submarine program leak

    October 3, 2023

    Prosecutors yesterday said they are investigating accusations of interference with the nation’s submarine program and that details of it were leaked, in what would be a serious breach of national security. Taiwan unveiled its first domestically developed submarine on Thursday last week, a major step in a project aimed at bolstering the nation’s defense and deterrence ...

  • Data breaches putting domestic abuse victims’ lives at risk, says UK watchdog

    September 27, 2023

    Councils, police forces and hospitals are putting women’s lives at risk by accidentally disclosing domestic abuse victims’ addresses to perpetrators, the UK’s information watchdog has said. John Edwards, the information commissioner, who has reprimanded seven organisations in just over a year for data breaches affecting victims of abuse, said: “This is a pattern that must ...

  • Microsoft AI researchers accidentally exposed terabytes of internal sensitive data

    September 18, 2023

    Microsoft AI researchers accidentally exposed tens of terabytes of sensitive data, including private keys and passwords, while publishing a storage bucket of open source training data on GitHub. In research shared with TechCrunch, cloud security startup Wiz said it discovered a GitHub repository belonging to Microsoft’s AI research division as part of its ongoing work ...

  • UK: Electoral Commission failed basic security test before hack

    September 5, 2023

    The Electoral Commission has confirmed it failed a basic cyber-security test around the same time hackers gained entry to the organisation. A whistleblower told the BBC that the Commission was given an automatic fail during a Cyber Essentials audit. Last month the Commission revealed that “hostile actors” accessed its emails and potentially the data of 40 ...

  • PSNI data breach: Two men released after Terrorism Act arrests

    September 3, 2023

    Two men have been released after being arrested by detectives investigating a major data breach by the Police Service of Northern Ireland (PSNI). The data was accidentally shared in August and included the surname and initials of 10,000 PSNI employees. The men, aged 21 and 22, were arrested under the Terrorism Act after a search in ...

  • Northern Ireland: Man arrested on suspicion of terror offence linked to PSNI data breach released

    August 17, 2023

    A man arrested by detectives investigating criminality linked to last week’s major PSNI data breach has been released on bail to allow for further police enquiries. The 39-year-old man had been detained following a search in Lurgan, Co Armagh on Wednesday. He had been questioned on suspicion of collection of information likely to be of use ...