iLoungeiLounge
  • News
    • Apple
      • AirPods Pro
      • AirPlay
      • Apps
        • Apple Music
      • iCloud
      • iTunes
      • HealthKit
      • HomeKit
      • HomePod
      • iOS 13
      • Apple Pay
      • Apple TV
      • Siri
    • Rumors
    • Humor
    • Technology
      • CES
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Font ResizerAa
iLoungeiLounge
Font ResizerAa
Search
  • News
    • Apple
    • Rumors
    • Humor
    • Technology
    • Daily Deals
    • Articles
    • Web Stories
  • iPhone
    • iPhone Accessories
  • iPad
  • iPod
    • iPod Accessories
  • Apple Watch
    • Apple Watch Accessories
  • Mac
    • MacBook Air
    • MacBook Pro
  • Reviews
    • App Reviews
  • How-to
    • Ask iLounge
Follow US

News › iPhone

iPhone

Rogue apps could affect non-jailbroken iPhones

Last updated: May 16, 2021 4:58 pm UTC
By Jesse Hollington

A Swiss iPhone developer has published research that indicates that security vulnerabilities affecting the iPhone are not limited to jailbroken iPhones. Developer Nicholas Seriot has created a proof of concept app called SpyPhone as a demonstration of how Apple’s own APIs could be misused to read or edit a user’s address book or gain access to a user’s web surfing history or recent location information.


For such attacks to succeed, a malicious application would still need to get past Apple’s App Store approval process to be available for non-jailbroken iPhones, however this is not outside of the realm of possibility as such an app would not require the use of any exploits or third-party APIs, and the spyware portion could be hidden by delayed activation or an encrypted payload.

The security researcher detailed these potential iPhone privacy risks in a talk he delivered in Geneva on Wednesday, during which he also outlined possible defense strategies, suggesting that Apple should design the iPhone OS to require users to authorize read or read-write access by iPhone applications to potentially sensitive on-device information such as the Address Book, add firewall functionality to the device and ensure the keyboard cache is not as readily available to third-party applications.

(via The Register).

.

Latest News
15-inch M5 MacBook Air 512GB Is $150 Off
15-inch M5 MacBook Air 512GB Is $150 Off
1 Min Read
Apple Will Use OLED Display Sourced By Samsung
Apple Will Use OLED Display Sourced By Samsung
1 Min Read
iPhone 18e and iPhone Air 2 to Release Next Year
iPhone 18e and iPhone Air 2 to Release Next Year
1 Min Read
Price Range for Foldable iPhone to be Revealed
Price Range for Foldable iPhone to be Revealed
1 Min Read
Anker Prime 3in1 Wireless Charging Station is $29 Off
Anker Prime 3in1 Wireless Charging Station is $29 Off
1 Min Read
Foldable iPhone Held Back Due to Snags in Manufacturing
Foldable iPhone Held Back Due to Snags in Manufacturing
1 Min Read
MacBook Neo Was a Huge Success; Apple Is Now Facing a Dilemma
MacBook Neo Was a Huge Success; Apple Is Now Facing a Dilemma
1 Min Read
New Games Coming to Apple Arcade
New Games Coming to Apple Arcade
1 Min Read
Apple Watch Ultra 3 is $99 off
Apple Watch Ultra 3 is $99 off
1 Min Read
Next-Gen MacBook Neo to Get A19 Pro Chip As Early As Next Year
Next-Gen MacBook Neo to Get A19 Pro Chip As Early As Next Year
1 Min Read
iPhone Fold Facing Delays
iPhone Fold Facing Delays
1 Min Read
Foldable iPhone May Have Ultra Branding
Foldable iPhone May Have Ultra Branding
1 Min Read

iLounge logo

iLounge is an independent resource for all things iPod, iPhone, iPad, and beyond. iPod, iPhone, iPad, iTunes, Apple TV, and the Apple logo are trademarks of Apple Inc.

This website is not affiliated with Apple Inc.
iLounge © 2001 - 2025. All Rights Reserved.
  • Contact Us
  • Submit News
  • About Us
  • Forums
  • Privacy Policy
  • Terms Of Use
Welcome Back!

Sign in to your account

Lost your password?