Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 18 submissions in the queue.
posted by janrinok on Thursday June 18 2015, @05:52PM   Printer-friendly
from the we-need-to-get-this-right dept.

Researchers have uncovered huge holes in the application sandboxes protecting Apple's OS X and iOS operating systems, a discovery that allows them to create apps that pilfer iCloud, Gmail, and banking passwords and can also siphon data from 1Password, Evernote, and other apps.

The malicious proof-of-concept apps were approved by the Apple Store, which requires all qualifying submissions to treat every other app as untrusted. Despite the supposed vetting by Apple engineers, the researchers' apps were able to bypass sandboxing protections that are supposed to prevent one app from accessing the credentials, contacts, and other resources belonging to another app. Like Linux, Android, Windows, and most other mainstream OSes, OS X and iOS strictly limit app access for the purpose of protecting them against malware. The success of the researchers' cross-app resource access—or XARA—attacks, raises troubling doubts about those assurances on the widely used Apple platforms.

"The consequences are dire," they wrote in a research paper titled Unauthorized Cross-App Resource Access on MAC OS X and iOS . "For example, on the latest Mac OS X 10.10.3, our sandboxed app successfully retrieved from the system's keychain the passwords and secret tokens of iCloud, email and all kinds of social networks stored there by the system app Internet Accounts, and bank and Gmail passwords from Google Chrome."


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by Tork on Thursday June 18 2015, @06:33PM

    by Tork (3914) Subscriber Badge on Thursday June 18 2015, @06:33PM (#197917)

    also it seems the "keyboard" in samsung galaxy devices phones-home to get "updates" and if a foreign wifi AP is used it could possibility impersonate the "update keyboard server" thus leading the galaxy to download a fake keyboard ...

    Now don't you worry, pretty soon Samsung will fix that problem and you'll be able to buy a new phone to get the update!

    --
    🏳️‍🌈 Proud Ally 🏳️‍🌈
    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 0) by Anonymous Coward on Thursday June 18 2015, @08:36PM

    by Anonymous Coward on Thursday June 18 2015, @08:36PM (#197969)

    Update has been given to the carriers, the carriers of course have not implemented it. But continue with your baseless bashing.

    • (Score: 0) by Anonymous Coward on Thursday June 18 2015, @08:42PM

      by Anonymous Coward on Thursday June 18 2015, @08:42PM (#197972)
      Basically all you really said was: "They used lube."