Apple has known about major zero-day flaws in its iOS and OS X operating systems for at least eight months, but the flaws are still present.

This is the claim made by six university researchers from Indiana University, Peking University and the Georgia Institute of Technology, who said they informed Apple of the flaws back in October 2014.

Keychain Compromised

The security holes in both iOS and Mac OS X allows a malicious app to steal passwords from Apple’s Keychain, as well as both Apple and third-party apps, with being detected.

A research paper outlining the flaws can be found here.

According to the Register, the researchers not only cracked Apple’s keychain, but they also broke app sandboxes and bypassed Apple App Store security checks. The team were able to upload malware to the Apple app store and passed Apple’s notoriously stringent vetting process, without triggering any alerts.

The team also raided the keychain (the password management system in OS X developed by Apple) to steal a number of passwords, including the native Mail app, iCloud and anything that was stored in Google Chrome.

“The consequences of these attacks are very serious, including leaks of user passwords, secret tokens and all kinds of sensitive documents,” said the researchers in their paper. “Our research shows that fundamentally the problem comes from lack of authentication during app-to-app and app-to-system interactions, and further proposes new techniques to detect and mitigate such a threat.”

The team said they had informed Apple back in October, and the iPad maker had asked the researchers to withhold publishing news of the flaws for six months.

Nine months later and that time has well and truly passed, and the researchers have still not heard back from Apple on the matter.

Even worse, the researchers warn that the flaws are still present in Apple’s current operating systems.

Tardy Response?

This is not the first time that Apple has been found wanting in fixing security vulnerabilities in a timely manner. In 2012 for example, Apple was criticised by security researchers who claimed it did not react fast enough to kill off a prevalent malware strain, called Flashback.

Apple has enjoyed a good security reputation in the past, but it clear that its operating systems do contain a number of vulnerabilities. Earlier this month for example, researchers warned that cybercriminals could use an iOS vulnerability to hack Apple Pay.

And late last year, it was discovered that Apple products in China that use Mac OS or iOS are under attack by a new family of malware.

Last November Apple had to develop a patch for another serious vulnerability, called “Rootpipe”. That flaw gave hackers admin privileges on a compromised Mac. To make matters worse, the hackers could exploit the flaw to give themselves the highest admin level, known as root access.

Last July Apple fixed a number of bugs and security flaws in an update to OS X Mavericks, and there have been many other flaws and vulnerabilities over the years as well.

What do you know about Internet security? Find out with our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Elon Musk’s X Head Of Global Affairs Resigns

X's global affairs head, Nick Pickles, confirms departure after a decade working at the platform…

1 day ago

CMA Halts Probe Into Microsoft’s Inflection AI Staff Hiring

British competition regulator closes investigation into Microsoft's hiring of Inflection AI staff, which it deems…

2 days ago

Telegram’s Pavel Durov Speaks Out Against French Charges

First public response made by Telegram CEO Pavel Durov, after arrest in France over alleged…

2 days ago

US Probes Four-Vehicle Crash Involving AI Driver Assistance

US authorities probe fatal four-vehicle crash caused by Ford Mustang Mach-E electric vehicle using BlueCruise…

3 days ago

Vestager To Step Down As EU Competition Chief

Margrethe Vestager set to step down as EU competition commissioner after a decade in office…

3 days ago

EU Seeks Industry Views On Google DMA Compliance

EU regulators to seek views from industry players on Google's DMA compliance plans ahead of…

3 days ago