HomeSecurityiOS URL Scheme Allows App-in-the-middle Attacks

iOS URL Scheme allows App-in-the-middle attacks

Scheme Some researchers have discovered a new app-in-the-middle attackthat allows a malicious appinstalled on iOS device to steal sensitive information from other apps using the Custom URL Scheme.

By default, in Apple 's operating system , each app runs in its own sandbox . This helps ensure that apps installed on the same device don't have access to the data of other apps.

On the other hand, there are some methods of sending and receiving some limited data between applications.

One of these methods is URL Scheme, also known as Deep Linking. This allows users to open an application via URLs (e.g. facetime://, whatsapp://, fb-messenger://).

For example, when you click “Sign in with Facebook,” it opens directly to the Facebookinstalled on your device and automatically bypasses authentication.

iOS URL Scheme allows App-in-the-middle attacks

The researchers noted that Apple does not clearly specify which apps will use specific keywords for its Custom URL Scheme. This means that different apps on an device can use the same URL Scheme. Therefore, sensitive data from another app could be exposed and exploited by hackers.

"This vulnerability is particularly critical if the login process of application A is related to application B," the researchers said.

The researchers provided an example of how the attack could be carried out, which you can see here.

If a malicious application has the same Custom URL Scheme as another application installed on the device, it can trick the other (applications) into sharing sensitive user data. It can also perform unauthorized actions, such as privacy violations, exposure to pop-up ads , and more.

Researchers have discovered many cases where ads were displayed to victims through this feature. Hackers are trying to create malicious applications that will have the same Custom URL Scheme as popular applications (wechat://, line://, fb://, fb-messenger://, etc.) in order to deceive more and more users.

Since the ability to exploit this vulnerability depends on the Custom URL Scheme, application developers should review their applications and make the necessary fixes to minimize the risk.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS