lcimeni / chase

0 stars 0 forks source link

NowSecure dynamic analysis: Sensitive Information Stored to Keychain #29

Open lcimeni opened 3 years ago

lcimeni commented 3 years ago

Finding Description

The data specified recovered from the iOS keychain. An attacker with the ability to decrypt the keychain may get access to the data. This attack requires physical access to the device, specialized tools, and a specialized skill set.

Steps to Reproduce

While the app is running on a physical device, iOS Keychain entries are monitored during dynamic analysis. After interacting with the app, the data specified was recovered from the keychain on the device.

Risk and Regulatory Information

Severity: info

Application

See more detail in the NowSecure Report