logo

282 iOS Apps Found Leaking LLM API Credentials in Network Traffic

ID: 522c2ea5-ed8e-5f8c-b085-40309f309a5f

STIX ID: report--522c2ea5-ed8e-5f8c-b085-40309f309a5f

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Divya

...
...

Researchers using a dynamic MITM and VPN-based tool called LLMKeyLens analyzed 444 LLM-enabled iOS apps and found 282 (64%) leaking provider credentials or backend access mechanisms in network traffic; 146 were classified as fully exploitable. The report categorizes leakage into plaintext API keys, JWT/opaque tokens to proxy backends, and unauthenticated backend relays, documents limited remediation after disclosure, and urges authenticated server-side proxies, strict JWT lifecycles, and layered traffic protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.