Security researchers from Pangu Lab, a well-known company that provides iOS jailbreaks, said on Monday that they have found a vulnerability that they believe affects around 10% of all iOS apps.
Researchers described the issue —which they named ZipperDown— as "a common programming error, which leads to severe consequences such as data overwritten and even code execution in the context of affected apps."
15,978 out of 168,951 iOS apps are most likely affected
Pangu Lab said it created an automated scan rule to search for ZipperDown in iOS apps. Researchers found that 15,978 out of the total of 168,951 iOS apps they scanned appeared to be impacted by the ZipperDown vulnerability, although, apps need to be manually inspected to confirm that they are affected.
We confirmed several iOS apps with more than 100 millions users are vulnerable to #ZipperDown#, and found more than 10k iOS apps might have the same or similar issues. Check http://zipperdown.org and contact us for details and fix if your app is in the list.
The list of vulnerable apps also includes several high-profile iOS apps that have more than 100 million users, such as Weibo, MOMO, NetEase Music, QQ Music, and Kwai.
Researchers also published a demo video exploiting ZipperDown in the Weibo app to achieve code execution rights.
Devs of vulnerable apps have to contact the researchers
"Due to the large amount of potentially affected apps, we cannot verify all the results precisely," Pangu Lab said.
In addition, because so many apps are affected, researchers couldn't contact the developers of each app individually to inform them of the issue.
The company is asking the developers of apps found on its list of potentially affected apps to contact the research team to receive details about the ZipperDown vulnerability, so each developer can test and fix his application.
If you were the developer or vender of the apps on the list, you are welcome to contact us. We would share you the detail of ZipperDown, and let us cooperatively fix the potential issue in your app. We would also appreciate if you could notify us in the case that your listed app is not vulnerable. The best way to reach us is the following Email: zipperdown@pwnzen.com.
Android also affected
Pangu Lab researchers also said that Android applications are also affected by similar issues and that they will release more details in the future.
The good news is that exploiting ZipperDown is not as straightforward as other vulnerabilities and an attacker must be in a network position to hijack or spoofing traffic to the device.
Furthermore, "the sandbox on both iOS and Android can effectively limit ZipperDown’s consequence," researchers said.