Feeds.4Sysops 282 iOS Apps Expose LLM API Credentials via Network Traffic
Article Content
- •282 iOS apps were found leaking LLM API credentials through network traffic.
- •The vulnerabilities affect a wide range of app categories, including productivity and education.
- •Many of the identified issues remain unpatched despite responsible disclosure.
A study by Wake Forest University revealed that 282 out of 444 analyzed iOS applications with AI features are leaking Large Language Model (LLM) API credentials through network traffic. This vulnerability affects apps across 13 categories, including productivity and education. The exposed credentials could lead to unauthorized access and abuse of LLM accounts and cloud resources. Researchers found that many of these issues remain unpatched despite responsible disclosure efforts. The findings indicate a systemic problem within the iOS ecosystem regarding the misuse of LLM provider APIs. The study emphasizes the need for improved security measures in mobile app development. Current status shows that the vulnerabilities are still present and unaddressed in many applications.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…