logo

Hundreds of AI-powered iOS apps found exposing credentials

ID: 555414a8-4efe-596e-af1d-fc498fd288b6

STIX ID: report--555414a8-4efe-596e-af1d-fc498fd288b6

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Sinisa Markovic

...
...

Researchers analyzed 444 iOS apps with LLM features and found 282 (26%) exposing exploitable credentials or backend access mechanisms—136 exposed authentication tokens, 92 allowed unauthenticated backend access, and 54 exposed plaintext API keys (28 of which also exposed system prompts). The leaks spanned productivity, entertainment, lifestyle, education, utilities, and health & fitness apps, affected both small and popular apps, and persisted in many cases after responsible disclosure, leaving a substantial portion still exploitable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.