logo

Looting iOS App's Cache.db

ID: a8e6e5c2-88c1-56c8-8194-b547e16713e0

STIX ID: report--a8e6e5c2-88c1-56c8-8194-b547e16713e0

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report describes an insecure-by-default behavior in iOS mobile applications where NSURLSession caches network responses to an unencrypted Cache.db SQLite database that commonly contains session tokens, credentials, and sensitive server data. It details attack paths for obtaining Cache.db (device access, iCloud or local backups), and provides step-by-step techniques to extract and convert embedded binary PLIST blobs from Cache.db for discovery of exposed secrets, along with mitigation recommendations for developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.