An iOS 10 flaw exposes your backed up iPhone data to hackers
Vulnerability makes it simple for hackers to crack users' backup passwords

Apple'siPhonesand iPads running the iOS 10 operating system are exposed to a security flaw that allows credentials to be stolen from backups, according to a security firm.
Russian iPhone hacking firm Elcomsoft claimed to uncover the iOS 10 vulnerability, after the OS was released on 13 September, stating that it weakened backup security protection, thus making it simple for hackers to crack passwords used for backups of iOS devices stored on Macs and PCs.
Elcomsoft researcher Oleg Afonin, who helped find the flaw,said in a blog post that while iPhones and iPads are very secure, and any acquisition method gets increasingly difficult with every generation of the iOS operating system, there's still a way for hackers to get into users' backup data.
"Forcing an iPhone or iPad to produce an offline backup and analysing resulting data is one of the very few acquisition options available for devices running iOS 10," Afonin explained. "Local backups are easy to produce if the iPhone is unlocked. However, you may be able to produce a local backup even if the phone is locked by using a pairing record extracted from a trusted computer."
He added: "If you are able to break the password, you'll be able to decrypt the entire content of the backup including the keychain. At this time, logical acquisition remains the only acquisition option available for iPhone 5s, 6/6 Plus, 6s/6s Plus and 7/7 Plus running iOS 10 that offers access to device keychain."
According to Afonin, the flaws also mean cracking efforts against iOS 10 backups are 2,500 times faster compared to similar efforts against iOS 9, and if a cyber crook is successful, the attack will grant access to device keychains.
Apple said it is currently looking to release a patch to fix to the problem, and will address the flaws in an upcoming security update, adding that it did not affect iCloud backups.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"We're aware of an issue that affects the encryption strength for backups of devices on iOS 10 when backing up to iTunes on the Mac or PC," said Apple in a statement. "We recommend users ensure their Mac or PC are protected with strong passwords and can only be accessed by authorised users. Additional security is also available with FileVault whole disk encryption."
-
M&S suspends online sales as 'cyber incident' continues
News Marks & Spencer (M&S) has informed customers that all online and app sales have been suspended as the high street retailer battles a ‘cyber incident’.
By Ross Kelly
-
Manners cost nothing, unless you’re using ChatGPT
Opinion Polite users are costing OpenAI millions of dollars each year – but Ps and Qs are a small dent in what ChatGPT could cost the planet
By Ross Kelly
-
Capita tells pension provider to 'assume' nearly 500,000 customers' data stolen
Capita told the pension provider to “work on the assumption” that data had been stolen
By Ross Kelly
-
Gumtree site code made personal data of users and sellers publicly accessible
News Anyone could scan the website's HTML code to reveal personal information belonging to users of the popular second-hand classified adverts website
By Connor Jones
-
Pizza chain exposed 100,000 employees' Social Security numbers
News Former and current staff at California Pizza Kitchen potentially burned by hackers
By Danny Bradbury
-
83% of critical infrastructure companies have experienced breaches in the last three years
News Survey finds security practices are weak if not non-existent in critical firms
By Rene Millman
-
Identity Automation launches credential breach monitoring service
News New monitoring solution adds to the firm’s flagship RapidIdentity platform
By Praharsha Anand
-
Neiman Marcus data breach hits 4.6 million customers
News The breach took place last year, but details have only now come to light
By Rene Millman
-
Indiana notifies 750,000 after COVID-19 tracing data accessed
News The state is following up to ensure no information was transferred to bad actors
By Rene Millman
-
Pearson fined $1 million for downplaying severity of 2018 breach
News The SEC found the London-based firm made “misleading statements and omissions” about the intrusion
By Rene Millman