iLoungeiLounge
  • News
    • Apple
      • AirPods Pro
      • AirPlay
      • Apps
        • Apple Music
      • iCloud
      • iTunes
      • HealthKit
      • HomeKit
      • HomePod
      • iOS 13
      • Apple Pay
      • Apple TV
      • Siri
    • Rumors
    • Humor
    • Technology
      • CES
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Font ResizerAa
iLoungeiLounge
Font ResizerAa
Search
  • News
    • Apple
    • Rumors
    • Humor
    • Technology
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Follow US

News › Apple

AppleApps

Hackers use app to steal passwords, data in iOS and OS X

Last updated: May 14, 2021 3:19 pm UTC
By Dan Pye
Hackers use app to steal passwords, data in iOS and OS X

University researchers have exposed a security flaw in iOS and OS X that lets an installed app exploit Apple’s cross-app resource sharing and communication to steal passwords from other apps and Apple’s Keychain, The Register reports. The team says they were able to upload their malware into an app that successfully passed the App Store’s vetting process. Once the app was downloaded, the researchers were able to raid users’ Keychain to steal passwords for iCloud, the Mail app and anything stored within Google’s Chrome browser.


Hackers use app to steal passwords, data in iOS and OS X

The team was able to steal banking credentials from Chrome, copy photos from WeChat and gain access to popular cloud service Evernote. Nearly 90 percent of a large sample of OS X and iOS apps were found to be “completely exposed” to the attack. Lead researcher Luyi Xing said his team informed Apple of the problem in October 2014 and complied with Apple’s request to hold off publishing the research for 6 months, but hasn’t heard back from the company since delivering an advance copy of the findings to Apple in February.


Apple didn’t comment on the story, but Google’s Chromium security team has since removed Keychain integration for Chrome, saying the security flaw probably can’t be solved at the application level. AgileBits, which owns browser extension 1Password, said their company hadn’t found a way to fend off the attacks four months after the team’s disclosure. Since the malware was delivered in an app that got past Apple’s vetting process, the only protection for iOS and OS X users at this point is to scrutinize the developer before downloading an app and be wary of login prompts for things usually handled by Keychain.


Latest News
The Apple Watch Series 11 46mm GPS Is $100 Off
The Apple Watch Series 11 46mm GPS Is $100 Off
1 Min Read
Clamshell Style iPhone Being Looked Into By Apple
Clamshell Style iPhone Being Looked Into By Apple
1 Min Read
Foldable iPhones May Have the Largest Battery Ever
Foldable iPhones May Have the Largest Battery Ever
1 Min Read
Apple and TSMC’s 10-Year Collaboration May Be Ending
Apple and TSMC’s 10-Year Collaboration May Be Ending
1 Min Read
The 13-inch M5 iPad Pro 256GB Wi-Fi Is $149 Off
The 13-inch M5 iPad Pro 256GB Wi-Fi Is $149 Off
1 Min Read
M5 Pro and M5 Max Chips for the MacBook Pro could Roll Out with macOS 26.3
M5 Pro and M5 Max Chips for the MacBook Pro could Roll Out with macOS 26.3
1 Min Read
Mac Ordering Process Revamped
Mac Ordering Process Revamped
1 Min Read
Check Signed By Steve Wozniak and Steve Jobs Sold For $2.4 Million
Check Signed By Steve Wozniak and Steve Jobs Sold For $2.4 Million
1 Min Read
The Anker 140W 4-Port GaN USB-C Charger is $35 Off
The Anker 140W 4-Port GaN USB-C Charger is $35 Off
1 Min Read
No iPhone Air 2 This Year, according to Latest Report
No iPhone Air 2 This Year, according to Latest Report
1 Min Read
New Report Corroborates Split iPhone Release Dates
New Report Corroborates Split iPhone Release Dates
1 Min Read
Apple Losing More Researchers As They Plan To Release 2 Siri Versions
Apple Losing More Researchers As They Plan To Release 2 Siri Versions
1 Min Read

iLounge logo

iLounge is an independent resource for all things iPod, iPhone, iPad, and beyond. iPod, iPhone, iPad, iTunes, Apple TV, and the Apple logo are trademarks of Apple Inc.

This website is not affiliated with Apple Inc.
iLounge © 2001 - 2025. All Rights Reserved.
  • Contact Us
  • Submit News
  • About Us
  • Forums
  • Privacy Policy
  • Terms Of Use
Welcome Back!

Sign in to your account

Lost your password?