Site icon What's New On The Net

Security firm finds 76 popular iOS apps vulnerable – News

47711

Image from Iconfinder

A bunch of iOS apps were found to be “vulnerable to silent interception of (normally) TLS-protected data while in use”, according to a report.

Writing in Medium, CEO of Sudo Security Group Will Strafach said it was while doing the development of their Web-based mobile app analysis service verify.ly, that they had decided it was essential to have a clear understanding of the most common security issues which plagued mobile applications today.

Automatically scanning the binary code of applications within the Apple App Store en-masse allowed us to get a vast amount of information about these security issues.Our system flagged hundreds of applications as having a high likelihood of vulnerability to data interception, but at this time I will be posting details of the connections and data which I was able to fully confirm as vulnerable using a live iPhone running iOS 10 and a “malicious” proxy to insert an invalid TLS certificate into the connection for testing.

 

To read the rest of Will’s post, click here.

 

 

•Share This•

Exit mobile version