Researchers analyzing 444 AI-powered iOS apps found that 282 of them exposed exploitable LLM API credentials or backend access mechanisms via network traffic interception. The vulnerability stems from insecure implementation of AI features across numerous app categories, allowing attackers to intercept and steal these credentials. The article does not provide specific CVSS scores, affected version ranges, fixed versions, or workarounds for the reported applications.
Mobile app developers are packing AI features into everything from writing assistants to productivity tools and lifestyle apps. New research shows that securing access to those services remains a challenge. LLM API credential leakage via network traffic interception (Source: Research paper) Researchers from Wake Forest University analyzed 444 iOS applications with LLM features and found 282 that exposed exploitable credentials or backend access mechanisms. The affected apps covered 13 categories, including productivity, entertainment, lifestyle, education, … More → The post Hundreds of AI-powered iOS apps found exposing credentials appeared first on Help Net Security .