Research on iOS apps shows widespread exposure of secrets


Researchers found that most of the apps available on Apple’s App Store leak at least one hard-coded secret.

The researchers looked at 156,000 iOS apps and discovered more than 815,000 hardcoded secrets, including very sensitive secrets like keys to cloud storage, various Application Programming Interfaces (APIs), and even payment processors. The researchers noted how: “The average app’s code exposes 5.2 secrets, and 71% of apps leak at least one secret.” Secrets hard-coded in the source code of the apps are considered exposed because they are relatively easy to find and abuse by cybercriminals.

Read more…
Source: Malwarebytes Labs


Sign up for our Newsletter


Related:

  • Data leak at VW subsidiary affects 800,000 electric cars

    December 27, 2024

    A data leak at the software company Cariad, a subsidiary of German car manufacturer Volkswagen (VW), left the personal details of electric car owners in Europe available online for months, Germany’s Spiegel news magazine reported on Friday. The movement data of 800,000 vehicles and contact information of the owners was accessible via the Amazon cloud storage ...

  • AI chatbot provider exposes 346,000 customer files, including ID documents, resumes, and medical records

    December 3, 2024

    Researchers have discovered a huge Google Cloud Storage bucket, found freely accessible on the internet and containing a treasure trove of personal information. AI startup WotNot provides companies with the ability to create their own customized chatbot. The company reportedly has 3,000 customers including some household family names. But the way its solution is set up ...

  • Russia toughens penalties for data leaks

    November 30, 2024

    Russian President Vladimir Putin signed laws that toughen penalties for illegal gathering and distribution of personal data. Administrative liability New fines are introduced. In particular, they total up to 15 mln rubles ($141,000) for illegal transfer of personal information and health details and up to 20 mln rubles ($188,000) for illegal transfer of biometric data. The ...

  • Westminster honeytrap victims named in Met Police email blunder

    November 29, 2024

    The Metropolitan Police has apologised to victims of the Westminster “honeytrap” scandal after it accidentally sent an email which named all of them. The force said it was referring itself to data watchdog the Information Commissioner over the breach. The Met is investigating flirtatious messages being sent by someone calling themselves “Charlie” or “Abi” to as ...

  • Exxon lobbyist investigated over hack-and-leak of environmentalist emails

    November 27, 2024

    The FBI has been investigating a longtime Exxon Mobil consultant over the contractor’s alleged role in a hack-and-leak operation that targeted hundreds of the oil company’s biggest critics, according to three people familiar with the matter. The operation involved mercenary hackers who successfully breached the email accounts of environmental activists and others, the sources told Reuters. ...

  • Ex-South Korean defence chief, officials accused of THAAD data leak to China

    November 20, 2024

    A former South Korean defence minister and three other senior officials who served in the previous Moon Jae-in administration have been accused of leaking intelligence on a US-built missile system to activists and China. The state auditor alleged that Jeong Kyeong-doo, ex-national security adviser Chung Eui-yong and two high-ranking officers passed information on the Terminal High ...