Skip to main content
  1. Home
  2. Computing
  3. Apple
  4. News

Report: Mac OS X and iOS security flaws allow for password theft

Add as a preferred source on Google

A group of researchers from universities including the Georgia Institute of Technology have found that Apple’s iOS and OS X have significant zero-day security flaws. Lead Researcher Luyi Xing and his colleagues detailed the holes in their report, “Unauthorized Cross-App Resource Access on MAC OS and iOS.” The flaws, which started making headlines on June 17, permit malicious apps to snag passwords from Apple’s Keychain and third-party apps, according to 9to5mac.

To conduct their research, the authors of the report uploaded malware to Apple’s App Store. In the process, they did not trigger alerts signifying that their app could steal passwords for services, including Mail and iCloud.

Recommended Videos

“Running it on hundreds of binaries, we confirmed the pervasiveness of the weaknesses among high-impact Apple apps,” the authors wrote in their report.

Xing says that his team reported the flaws to Apple in October 2014. Afterward, he complied with the company’s request to withhold the release of his report for six months, according to The Register. Thus far, Apple has not been immediately available for comment. However, the research team suspects that the security flaws are still present.

“We built end-to-end attacks on several high-impact apps (e.g., Facebook, Pinterest, etc.), identified the impacts of the threat over a thousand apps, and more importantly demonstrate that the attacks can be made stealthy (through different man-in-the-middle tricks on MAC OS and iOS, passing the stolen token to the victim app, to completely conceal the attack), which is nontrivial,” the report continues.

Thus far, much of the researchers’ work has been focused on Android security. This is one of the first reports that has been based on Apple’s security vulnerabilities. Xing and his team say that most of the problems stem from Apple’s cross-app resource sharing and communication methods.

Researchers concluded that approximately 90 percent of Mac and iOS apps were “completely exposed,” giving malware full access to sensitive data.

Krystle Vermes
Former Digital Trends Contributor
Krystle Vermes is a professional writer, blogger and podcaster with a background in both online and print journalism. Her…
MIT researchers found a new Spectre attack that can slip past Intel and AMD defenses
AMD Ryzen CPU inside a socket installed on a motherboard

Spectre has been haunting CPU security since 2018, and MIT researchers have now found another way to make it misbehave. The new TONTOU attack can bypass some of the defenses Intel and AMD have added over the years by exploiting a tiny gap in how those protections work. The research comes from Daniël Trujillo and Mengjia Yan at MIT's Computer Science and Artificial Intelligence Laboratory (CSAIL). Their findings show that even after a processor wipes or isolates information used by its branch predictor, there can be a brief window before that information is actually used. TONTOU, short for Time-of-Neutralization to Time-of-Use, attacks precisely that gap.

The tiny gap that TONTOU exploits

Read more
Microsoft accidentally gave Windows 11 users another OneDrive app, and you can’t easily remove it
Microsoft says the wider-than-intended rollout was an accident, but removing the app currently means removing OneDrive too.
Microsoft OneDrive Featured Graphic

Windows 11 users have been getting a new OneDrive app whether they asked for it or not. The problem? Microsoft says it wasn't supposed to happen. Microsoft has confirmed that its OneDrive Photos app was rolled out to Windows 11 PCs more broadly than intended, including enterprise machines where the app isn't even designed to work. The company says it is now working on a fix, but there's an awkward catch: users currently can't uninstall OneDrive Photos without removing the main OneDrive app too.

So, what exactly got installed?

Read more
Apple Reminders sucked for project management until I learned this feature
Your checklist deserves better. Here's how to turn Reminders into a proper Kanban board.
Apple reminders on Mac

For the longest time, I used Apple Reminders only for capturing quick tasks. Thanks to its Siri integration, Reminders let me add tasks quickly so nothing would fall through the cracks. However, when it came to managing big projects, I always moved to a more powerful task manager like OmniFocus or Things 3. 

That changed the day I stumbled onto the Column view. Apple added this feature with the iOS 17 and macOS Sonoma updates, and somehow I completely missed it. But once I discovered and got the hang of it, Reminders finally started to feel like a real project management tool instead of a glorified sticky note.

Read more