Research on iOS apps shows widespread exposure of secrets


Researchers found that most of the apps available on Apple’s App Store leak at least one hard-coded secret.

The researchers looked at 156,000 iOS apps and discovered more than 815,000 hardcoded secrets, including very sensitive secrets like keys to cloud storage, various Application Programming Interfaces (APIs), and even payment processors. The researchers noted how: “The average app’s code exposes 5.2 secrets, and 71% of apps leak at least one secret.” Secrets hard-coded in the source code of the apps are considered exposed because they are relatively easy to find and abuse by cybercriminals.

Read more…
Source: Malwarebytes Labs


Sign up for our Newsletter


Related:

  • Bot army risk as 3,000+ apps found spilling Twitter API keys

    August 2, 2022

    Want to build your own army? Engineers at CloudSEK have published a report on how to do just that in terms of bots and Twitter, thanks to API keys leaking from applications. Researchers at the company say they’ve uncovered 3,207 apps leaking Twitter API keys, which can be used to gain access to or even entirely ...

  • Walmart-controlled flight booking service suffers substantial data leak

    July 19, 2022

    An Indian flight booking website majority-owned by US retail colossus Walmart has experienced a data breach, but is saying very little about what happened or the risks to customers. News of the breach emerged on Monday, when customers received a message. While the message to customers assures them that “no sensitive information pertaining to your Cleartrip account” ...

  • How data on a billion people may have leaked from a Chinese police dashboard

    July 10, 2022

    Details have emerged on how more than a billion personal records were stolen in China and put up for sale on the dark web, and it all boils down to a unprotected online dashboard that left the data open to anyone who could find it. More than 23TB of details apparently stolen from the Shanghai police ...

  • There are 24.6 billion sets of credentials up for sale on the dark web

    June 20, 2022

    More than half of the 24.6 billion stolen credential pairs available for sale on the dark web were exposed in the past year, the Digital Shadows Research Team has found. Data recorded from last year reflected a 64 percent increase over 2020’s total (Digital Shadows publishes the data every two years), which is a significant slowdown ...

  • A hacker group said it has broken into the Israeli electricity network

    June 16, 2022

    A hacker group identifying itself as the “Moses Staff” said it has broken into the Israeli electricity network, vowing to plunge the regime into darkness. The group said on Wednesday it had targeted the Israel Electric Corporation, the largest supplier of electrical power in the occupied territories, as well as Dorad Energy Ltd., which serves customers ...

  • Australian National Disability Insurance Scheme provider breached and treating its database as compromised

    May 31, 2022

    CTARS, the makers of a cloud-based client management system used by the Australian National Disability Insurance Scheme (NDIS) as well as disability services, out of home care, and children’s services, has revealed it was breached on May 15 and found the data posted to the dark web a week later. “Although we cannot confirm the details ...