iPhone & iPad users at risk of Masque Attack II iOS hack
Hack could leave enterprise users open to data theft, claims FireEye researchers


iPad and iPhone users are being warned about the discovery of the Masque Attack II iOS hack, which could potentially leave their data open to theft.
FireEye researchers Hui Xue, Zhaofeng Chen, Song Jin, Yulong Zhang and Tao Wei discovered the first edition of the Masque flaw last November, which could allow malicious apps to replace existing enterprise ones on devices. Now the researchers have discovered a sequel.
The group explained in a blog post: "We find that when calling an iOS URL scheme, iOS launches the enterprise-signed app registered to handle the URL scheme without prompting for trust. It doesn't matter whether the user has launched that enterprise-signed app before."
FireEye said even if the user always clicks Don't Trust' to such apps, iOS still launches that enterprise-signed app directly on calling its URL scheme, meaning it could cause unexpected results.
"In other words, when the user clicks on a link in SMS, iOS Mail or Google Inbox, iOS launches the target enterprise-signed app without asking for the user's Trust' or even ignoring the user's Don't Trust'," they continued.
This could enforce a malicious version of a real, safe enterprise app to launch instead, potentially causing the hackers to steal confidential data or corrupt the device.
FireEye is urging iOS users be cautious when clicking on unknown links, especially if they are sent to their device by SMS, email or MMS.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Users should update devices to 8.1.3 as soon as possible to mitigate the risk as much as possible," the company said. "Apple suggested defending against Masque Attack by the aid of the 'Don't Trust' prompt. We notified Apple that this was inadequate."

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
M&S suspends online sales as 'cyber incident' continues
News Marks & Spencer (M&S) has informed customers that all online and app sales have been suspended as the high street retailer battles a ‘cyber incident’.
By Ross Kelly
-
Manners cost nothing, unless you’re using ChatGPT
Opinion Polite users are costing OpenAI millions of dollars each year – but Ps and Qs are a small dent in what ChatGPT could cost the planet
By Ross Kelly
-
Apple iPad Air (2020) review: The executive’s choice
Reviews With the iPad Air’s most recent redesign, Apple has delivered the best bang-for-buck tablet money can buy
By Connor Jones
-
In praise of the early adopters
Opinion The IT industry needs early adopters like you – and tech that fell by the wayside should still be celebrated
By David Crookes
-
Apple is experimenting with attention sensors to save battery life
News Your next Apple device may shut down if you are not paying attention to it
By Justin Cupler
-
Apple unveils M1-powered iPad Pro and iMac at April 2021 event
News The new Apple Silicon hardware will be available to order from April 30
By Justin Cupler
-
iPad Air 2020 debuts with A14 Bionic chip and USB-C
News Apple touts its latest flagship tablet as the “most powerful” iPad Air ever
By Sarah Brennan
-
Apple reveals iPadOS at WWDC19
News Cupertino's tablet range breaks free of iOS with new dedicated software
By Jane McCallion
-
Best iPad apps for 2019
Best Our collection of the best and most popular iPad apps to download in 2019
By Connor Jones
-
Apple Event: New MacBook Air, iPad Pro and Mac mini launched
News Apple appeases fans with long-requested hardware refreshes
By Adam Shepherd