Researchers from security firm FireEye have uncovered a new bug in iOS that allows a malicious app to track and log in using a user's touch data while running in the background. The new exploit reportedly targets a flaw in iOS' multitasking capabilities "to access user data, and send it to a remote server."
To demonstrate the vulnerability, the researchers created a proof-of-concept (POC) of the malicious app’s actions and developed approaches to effectively bypass Apple’s App Store process. Once the app is installed on an iOS device, it starts recording what happens on the keyboard, data usage, home and power buttons, screen touches, and all Touch ID activity. All of this is recorded and stored!
The researchers also noted that the malicious app disables the iOS “Background App Refresh” setting so that you don’t disable the malicious app from recording data.
FireEye reports:
Note that our demo exploits the latest iOS 7.0.4 version on a non-jailbroken iPhone 5s device successfully. We have found that the same vulnerability also exists in iOS 7.0.5, 7.0.6 and 6.1.x versions. Based on the findings, potential attackers can use it either for phishing attacks or to trick the victim into installing a malicious application or exploit another remote vulnerability of certain applications, and then conduct surveillance in the background.
The team added that they are actively working with Apple to fix the issue. The news comes less than a week after Apple released the iOS 7.0.6 update to fix an SSL vulnerability that allowed hackers to obtain or modify data from Safari and other apps in supposedly secure sessions.



