Mobile menu toggle

Apple unaware of any iOS users targeted by Masque Attack

By

Thought WireLurker was bad? Wait till you meet Masque Attack. Photo: Jim Merithew/Cult of Mac
Thought WireLurker was bad? Wait till you meet Masque Attack. Photo: Jim Merithew/Cult of Mac

Following the discovery of the serious iOS vulnerability known as Masque Attack, Apple has issued a statement to iMore, claiming that it is not aware of users experiencing this problem, but that users should be aware of online malware that circumvents Apple’s existing security measures.

“We designed OS X and iOS with built-in security safeguards to help protect customers and warn them before installing potentially malicious software,” said an Apple spokesperson. “We’re not aware of any customers that have actually been affected by this attack. We encourage customers to only download from trusted sources like the App Store and to pay attention to any warnings as they download apps. Enterprise users installing custom apps should install apps from their company’s secure website.”

Masque Attack was discovered by the FireEye mobile security research team. It works by mimicking and replacing the legitimate apps installed on your iPhone with decoys which then steal personal information with users realizing it.

Below is a video showing how the attacks work:

While Masque Attacks are certainly serious, however, like the previous WireLurker vulnerability it should be noted that users have to download and install apps from outside the App Store and then hit “Trust” on the warning dialog boxes which come up.

Put simply, you have to consciously and wilfully ignore Apple’s built-in safeguards to be affected.

  • Subscribe to the Newsletter

    Our daily roundup of Apple news, reviews and how-tos. Plus the best Apple tweets, fun polls and inspiring Steve Jobs bons mots. Our readers say: "Love what you do" -- Christi Cardenas. "Absolutely love the content!" -- Harshita Arora. "Genuinely one of the highlights of my inbox" -- Lee Barnett.