Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
ai-platform-securityleaked-secret-api-keyidentity-authentication-vulnerabilitycloud-service-vulnerability

Hundreds of AI-Powered iOS Apps Exposed LLM Credentials and Backend Access

Updated 5d agoFirst seen Jun 22, 20262 sources

Researchers at Wake Forest University found widespread credential leakage in AI-enabled iOS apps, reporting that 282 of 444 tested applications exposed exploitable access to LLM services or supporting backends during normal use. The affected apps spanned 13 categories, including productivity, education, utilities, entertainment, lifestyle, and health and fitness, and included both niche titles and highly popular apps with millions of ratings. The exposed data created opportunities for attackers to abuse developers’ LLM accounts, consume cloud resources, and access backend services.

The study identified three recurring failure patterns: plaintext API keys sent directly to LLM providers, unauthenticated backend proxy endpoints, and replayable JWT bearer tokens with weak or broken expiration controls. Researchers said many apps lacked effective protections against traffic interception, and common defenses could be bypassed through VPN-based transparent capture. After responsible disclosure and a 90-day retest, remediation remained limited: about 28% of vulnerable apps had fixed the issues, while dozens remained exploitable because developers made little change or relied on fundamentally flawed authentication designs.

Share:
Hundreds of AI-Powered iOS Apps Exposed LLM Credentials and Backend Access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 22, 20266d ago

90-day retest finds limited remediation across affected iOS apps

After a 90-day retest following responsible disclosure, the researchers found remediation remained limited: 28% of vulnerable apps had fixed the issues, while many others remained exploitable due to no remediation or flawed authentication implementations.

Hundreds of AI-powered iOS apps found exposing credentials - Help Net Security

Researchers responsibly disclose the iOS app credential leakage issues

After identifying the insecure LLM integrations, the researchers carried out responsible disclosure to affected parties before later retesting the apps.

Hundreds of AI-powered iOS apps found exposing credentials - Help Net Security

Researchers analyze 444 LLM-enabled iOS apps and find widespread credential exposure

Researchers from Wake Forest University analyzed 444 iOS apps with confirmed LLM functionality and found that 282 exposed exploitable credentials or backend access mechanisms, including plaintext API keys, unauthenticated backend access, and replayable JWT bearer tokens.

Hundreds of AI-powered iOS apps found exposing credentials - Help Net Security
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Affected products
2 linked
IosAmazon Web Services
Organizations
6 linked
GoogleWake Forest UniversityLinkedinOpenaiXAmazon Web Services
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.