IOS security vulnerabilities allow attackers to replace installed Legal applications with malicious applications
Security company FireEye warned on its official blog that a security vulnerability on iOS devices allows attackers to replace installed Legal applications with malicious applications and steal password emails and other sensitive data. FireEye calls this Attack method Masque Attack. If a valid application uses the same Packet Identifier as a malicious application, attackers can trick victims into installing apps with fraudulent names, such as Angry Birds, to replace installed Angry Birds. FireEye said such attacks can be used to steal login information or other sensitive data from banks and emails. "This is a very large vulnerability that can be easily exploited," said Tao Wei, a FireEye Senior Research Scientist. FireEye informed apple of this vulnerability in July, company representatives said they were trying to fix the vulnerability.
OS X details: click here
This article permanently updates the link address: