iPhone & iPad users at risk of Masque Attack II iOS hack
Hack could leave enterprise users open to data theft, claims FireEye researchers


iPad and iPhone users are being warned about the discovery of the Masque Attack II iOS hack, which could potentially leave their data open to theft.
FireEye researchers Hui Xue, Zhaofeng Chen, Song Jin, Yulong Zhang and Tao Wei discovered the first edition of the Masque flaw last November, which could allow malicious apps to replace existing enterprise ones on devices. Now the researchers have discovered a sequel.
The group explained in a blog post: "We find that when calling an iOS URL scheme, iOS launches the enterprise-signed app registered to handle the URL scheme without prompting for trust. It doesn't matter whether the user has launched that enterprise-signed app before."
FireEye said even if the user always clicks Don't Trust' to such apps, iOS still launches that enterprise-signed app directly on calling its URL scheme, meaning it could cause unexpected results.
"In other words, when the user clicks on a link in SMS, iOS Mail or Google Inbox, iOS launches the target enterprise-signed app without asking for the user's Trust' or even ignoring the user's Don't Trust'," they continued.
This could enforce a malicious version of a real, safe enterprise app to launch instead, potentially causing the hackers to steal confidential data or corrupt the device.
FireEye is urging iOS users be cautious when clicking on unknown links, especially if they are sent to their device by SMS, email or MMS.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Users should update devices to 8.1.3 as soon as possible to mitigate the risk as much as possible," the company said. "Apple suggested defending against Masque Attack by the aid of the 'Don't Trust' prompt. We notified Apple that this was inadequate."

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Apple iPad Air (2020) review: The executive’s choice
Reviews With the iPad Air’s most recent redesign, Apple has delivered the best bang-for-buck tablet money can buy
By Connor Jones
-
In praise of the early adopters
Opinion The IT industry needs early adopters like you – and tech that fell by the wayside should still be celebrated
By David Crookes
-
Apple is experimenting with attention sensors to save battery life
News Your next Apple device may shut down if you are not paying attention to it
By Justin Cupler
-
Apple unveils M1-powered iPad Pro and iMac at April 2021 event
News The new Apple Silicon hardware will be available to order from April 30
By Justin Cupler
-
iPad Air 2020 debuts with A14 Bionic chip and USB-C
News Apple touts its latest flagship tablet as the “most powerful” iPad Air ever
By Sarah Brennan
-
Apple reveals iPadOS at WWDC19
News Cupertino's tablet range breaks free of iOS with new dedicated software
By Jane McCallion
-
Best iPad apps for 2019
Best Our collection of the best and most popular iPad apps to download in 2019
By Connor Jones
-
Apple Event: New MacBook Air, iPad Pro and Mac mini launched
News Apple appeases fans with long-requested hardware refreshes
By Adam Shepherd