Triadoro

Triadoro

  • Home
  • TECH
  • EDUCATION
  • MONEY
  • REVIEWS
  • APPS
  • NEWS
    • CREATIVE
    • GEAR
    • INSIGHTS
    • LAUNCH
    • WORLD
  • Contact Us !
Notification Show More
Latest News
Agility, leadership, and motivation that never dies In 1967
Inspiration
Scholarship Test Results- held on 1st Dec. 2024 for OGP 2026 (Offline & Online Guidance Program) at Bengaluru & Online | Integrated Foundation Program for UPSC CSE IAS 2026
INSIGHTS
Reviews 2.0: The new currency for content is tags
REVIEWS
Are you about to embark on your first journey with your baby
EDUCATION
SEO’s Relevance to Customer Reviews
REVIEWS
Aa

Triadoro

Triadoro

Aa
Search
  • Home
  • TECH
  • EDUCATION
  • MONEY
  • REVIEWS
  • APPS
  • NEWS
    • CREATIVE
    • GEAR
    • INSIGHTS
    • LAUNCH
    • WORLD
  • Contact Us !
Follow US
APPS

IPHONE APPS WITH FAKE LOGIN POP-UPS CAN STEAL YOUR PASSWORDS

Loknath Das
Last updated: 2017/10/12 at 4:00 PM
Loknath Das

Malicious iPhone apps can steal users’s personal information through fake login pop-ups, an Apple iOS app developer has revealed.

The vulnerability, which could potentially allow criminals to gain access to an iPhone owner’s Apple account, was demonstrated by mobile app developer Felix Krause in a blog post Tuesday.

Krause said the security loophole has been in place for many years and has yet to be addressed. A spokesperson for Apple did not immediately respond to a request for comment.

Keep Up With This Story And More By Subscribing Now

The password phishing scam is relatively simple for app developers to activate, and iPhone users may not even realize that they have been targeted.

iphone app steals passwords appleAn Apple iPhone smartphone appears as a silhouette in Zenica, Bosnia, on May 17, 2013. A security vulnerability has been discovered that could allow hackers to steal your passwords.REUTERS/DADO RUVIC

The “Sign in to iTunes Store” popup that appears as a prompt from Apple in some apps can be replicated by developers and placed into the app’s code as an alert.

“Users are trained to just enter their Apple ID password whenever iOS prompts you to do so,” Krause wrote in his blog describing the issue. “Those popups are not only shown on the lock screen, and the home screen, but also inside random apps.

“This could easily be abused by any app…Even users who know a lot about technology have a hard time detecting that those alerts are phishing attacks.”

Krause says users can protect themselves by hitting the home button on their iPhone if they suspect the login pop-up is fake. If pushing the button closes the app, and with it the pop-up, then it was a phishing attack.

So far this is just a proof-of-concept and no instances of the vulnerability have been discovered within iOS apps. In order for it to be remedied, Krause says that Apple could make adjustments to the way apps request Apple ID passwords.

apple iphone 8 plus battery explodingApple launched the iPhone 8 and 8 Plus at the GUM department store in Moscow on September 29.SEFA KARACAN/ANADOLU AGENCY/GETTY IMAGES

For example, rather than use a login pop-up, Apple could request iPhone users to input their username and password into the “settings” section of their phone.

iPhone owners can also enable two-factor authentication in order to access their Apple account.

Krause’s blog comes less than a week after an undocumented feature in the Uber app was uncovered that allowed the ride-hailing company to secretly record the screen of iPhone users.

Mobile security researcher Will Strafach posted the capability—known as “entitlement”—to Twitter, describing its presence in the app’s code as “very unusual.”

“It looks like no other third-party developer has been able to get Apple to grant them a private sensitive entitlement of this nature,” Strafach said. “Considering Uber’s past privacy issues I am very curious how they convinced Apple to allow this.”

[“Source-newsweek”]

TAGGED: Apps, Can, Fake, iPhone, Login, Passwords, Pop-Ups, Steal, with, Your

Breaking News

  • Agility, leadership, and motivation that never dies In 1967
  • Scholarship Test Results- held on 1st Dec. 2024 for OGP 2026 (Offline & Online Guidance Program) at Bengaluru & Online | Integrated Foundation Program for UPSC CSE IAS 2026
  • Reviews 2.0: The new currency for content is tags
  • Are you about to embark on your first journey with your baby
  • SEO’s Relevance to Customer Reviews
  • In 2025, the four best journaling apps
  • Can anyone rate the article in my school magazine?
  • 31 Best Blog Apps to Start, Run, and Expand Your Blog
  • Is Your MSP CMMC-Compliant? The Question Most Companies Forget to Ask Before a CMMC Assessment
  • Dozens of new mobile apps are coming to cars with Google built-in
  • How Long Does it Take to Make Money From Blogging (2025)
  • The Top 10 Free and Paid Note-Taking Apps in 2025
  • 15 blogs about education that every teacher should read
  • 9 ways to celebrate Reading Month
  • Four takeaways on the impact of cross-sector partnerships
  • Investing in trust: why trust matters more than ever in 2024
  • Hands-On Learning with Arduino Kits: Benefits and Strategies
  • Donald Trump’s new government cleanout focus on: The Training Division
  • Grasping Principal Cog wheels Versus Planetary Pinion wheels
  • The Celebration of Lights
  • MP Political Punch: Craft Of Legislative issues, Strict The travel industry, Father’s Structure and More
  • Martha Stewart made ready for powerhouses. Be that as it may, not every person finds her image enabling
  • The Historical backdrop of Quick Style
  • What Is an Able to use both hands Association?
  • Print’s not dead: the best magazines for visual communication motivation

Popular Post

  • Agility, leadership, and motivation that never dies In 1967
  • Scholarship Test Results- held on 1st Dec. 2024 for OGP 2026 (Offline & Online Guidance Program) at Bengaluru & Online | Integrated Foundation Program for UPSC CSE IAS 2026
  • Reviews 2.0: The new currency for content is tags
  • Are you about to embark on your first journey with your baby
  • SEO’s Relevance to Customer Reviews
  • In 2025, the four best journaling apps
  • Can anyone rate the article in my school magazine?
  • 31 Best Blog Apps to Start, Run, and Expand Your Blog
  • Is Your MSP CMMC-Compliant? The Question Most Companies Forget to Ask Before a CMMC Assessment
  • Dozens of new mobile apps are coming to cars with Google built-in
  • How Long Does it Take to Make Money From Blogging (2025)
  • The Top 10 Free and Paid Note-Taking Apps in 2025
  • 15 blogs about education that every teacher should read
  • 9 ways to celebrate Reading Month
  • Four takeaways on the impact of cross-sector partnerships
  • Investing in trust: why trust matters more than ever in 2024
  • Hands-On Learning with Arduino Kits: Benefits and Strategies
  • Donald Trump’s new government cleanout focus on: The Training Division
  • Grasping Principal Cog wheels Versus Planetary Pinion wheels
  • The Celebration of Lights
  • MP Political Punch: Craft Of Legislative issues, Strict The travel industry, Father’s Structure and More
  • Martha Stewart made ready for powerhouses. Be that as it may, not every person finds her image enabling
  • The Historical backdrop of Quick Style

Like Us !

Like Us !

You Might Also Like

APPS

In 2025, the four best journaling apps

April 8, 2025

31 Best Blog Apps to Start, Run, and Expand Your Blog

April 1, 2025
APPS

Dozens of new mobile apps are coming to cars with Google built-in

March 24, 2025
APPS

The Top 10 Free and Paid Note-Taking Apps in 2025

March 13, 2025

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?