Slashdot Mirror


MDM Vulnerability In Apple iOS Sandbox Facilitates 'Rogue Apps'

An anonymous reader writes: A vulnerability in Apple's iOS sandbox, which could affect personal information as well as configuration settings, has been discovered by Appthority's Enterprise Mobility Threat Team. It affects all mobile device management (MDM) clients, and any mobile applications distributed by an MDM that use the "Managed App Configuration" setting for private data. An attacker could potentially create a rogue app, perhaps masquerading as a productivity tool to increase the chances of it getting installed, and then distribute the attack by means of the iTunes store or "spear fishing" email attacks.

1 of 13 comments (clear)

  1. Re:Has been fixed in iOS 8.4.1 by Karlt1 · · Score: 3, Insightful

    And if these are managed devices, it doesn't matter that " 70% of iOS devices are not running the latest version of iOS". Whoever is responsible for managing the devices can tell which OS the device is running and tell the users to update.