AI-Powered iOS Apps Leaking LLM API Credentials Through Network Traffic
ID: 268196e2-bd17-5ee6-b6f8-959b12b7bb85
STIX ID: report--268196e2-bd17-5ee6-b6f8-959b12b7bb85
Feed Name: cybersecurityNews.com
An empirical study of 444 LLM-enabled iOS apps found 282 (64%) leaked exploitable LLM API credentials via plaintext keys, unauthenticated backend proxies, or leaked JWTs. Using a runtime MITM analysis framework (LLMKeyLens) on physical devices, researchers intercepted traffic, validated active credentials, and observed systemic issues such as long-lived or non-expiring tokens, exposed system prompts, weak interception resistance, and slow or incomplete remediation across affected apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
