FeedData BreachHundreds of iPhone apps found leaking OpenAI, Gemini credent...
Data BreachCyber Insider
8.0CRITICAL

Hundreds of iPhone apps found leaking OpenAI, Gemini credentials

📅 11 June 2026 at 17:06 UTC📰 Cyber InsiderView original source ↗
Hundreds of iPhone apps found leaking OpenAI, Gemini credentials

An academic study has found that LLM-powered iOS applications routinely expose API credentials that can be abused to access AI services. Researchers discovered that nearly two-thirds of tested apps leaked credentials or exposed backend access mechanisms, with many vulnerabilities remaining unfixed months after disclosure. A team of researchers in the US developed a framework called … The post Hundreds of iPhone apps found leaking OpenAI, Gemini credentials appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Hundreds of iPhone apps were found leaking OpenAI and Gemini credentials, exposing API keys and authentication tokens that can be abused to access AI services. The vulnerabilities remained unfixed for months after disclosure.

⚙️Technical Details
Affected Systems
iOS applicationsApple's App Store
Attack Vectors
Directly embedding plaintext API keys in requests sent to AI providersJWT bearer tokensUnauthenticated backend proxies
💥Impact Assessment
Severity: High
Who Is at Risk
Developers and users of affected iPhone apps, particularly those with productivity, entertainment, lifestyle, education, utilities, and health and fitness features.
🛡️Recommended Actions
1Enforce proper authentication and authorization on backend services
2Implement automated credential-leak detection in the App Store review process
3Offer clearer guidance and reference implementations for secure integrations with AI providers
📦Affected Products
iOS applicationsApple's App Store

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider
← Back to feed