logo

Too Easy – Adding Root CA’s to iOS Devices

ID: bec98886-df77-5714-a24e-b4c98772d174

STIX ID: report--bec98886-df77-5714-a24e-b4c98772d174

Feed Name: SensePost Blog

Threat Score
60/100

Date Published: 2016-03-23

Date Updated: 2026-04-29

...
...

This blog demonstrates how trivial it can be to push a malicious root CA or a signed configuration profile to iOS devices (via captive portals or delivered .mobileconfig files), which allows an attacker to perform HTTPS MitM and configure device settings — potentially including persistent MDM — with minimal overhead and only user interaction. The author shows the steps, UI screenshots, and explains that while this enables broad interception, certificate pinning (e.g., for recent iMessage traffic) mitigates some specific attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.