Sciweavers

CCS
2015
ACM

Cracking App Isolation on Apple: Unauthorized Cross-App Resource Access on MAC OS~X and iOS

8 years 7 months ago
Cracking App Isolation on Apple: Unauthorized Cross-App Resource Access on MAC OS~X and iOS
On modern operating systems, applications under the same user are separated from each other, for the purpose of protecting them against malware and compromised programs. Given the complexity of today’s OSes, less clear is whether such isolation is effective against different kind of cross-app resource access attacks (called XARA in our research). To better understand the problem, on the less-studied Apple platforms, we conducted a systematic security analysis on MAC OS X and iOS. Our research leads to the discovery of a series of high-impact security weaknesses, which enable a sandboxed malicious app, approved by the Apple Stores, to gain unauthorized access to other apps’ sensitive data. More specifically, we found that the inter-app interaction services, including the keychain, WebSocket and NSConnection on OS X and URL Scheme on OS X and iOS, can all be exploited by the malware to steal such confidential information as the passwords for iCloud, email and bank, and the secret ...
Luyi Xing, Xiaolong Bai, Tongxin Li, XiaoFeng Wang
Added 17 Apr 2016
Updated 17 Apr 2016
Type Journal
Year 2015
Where CCS
Authors Luyi Xing, Xiaolong Bai, Tongxin Li, XiaoFeng Wang, Kai Chen 0012, Xiaojing Liao, Shi-Min Hu, Xinhui Han
Comments (0)