Surprise! iOS Apps Just as Bad as Android at Security (Report)

Android and iOS apps are equally bad at guarding user data and maintaining security, finds a new report from Boston-based information-security consulting firm Positive Technologies.

Credit: Nebojsa Markovic/Shutterstock

(Image credit: Nebojsa Markovic/Shutterstock)

"An alarming number of apps are critically insecure," said Positive Technologies researcher Leigh-Anne Galloway in a press statement accompanying the report. "Stealing data from a smartphone usually doesn't even require physical access to the device."

A slightly larger percentage of Android apps (43% of those tested) than iOS apps (38%) had high-risk vulnerabilities, but the report says the overall difference was trivial. More iOS apps (74%) than Android apps (57%) suffered from weaknesses in security mechanisms. Overall, 76% of the apps failed to secure user data properly, which "could enable hackers to steal passwords, financial information, personal data, and correspondence."

Positive Technologies recommends that smartphone users examine the permissions each app requests and deny those that the app doesn't obviously need; use truly random PIN codes, and biometric authentication whenever possible; not root or jailbreak a device; update the operating system and apps regularly; not allow other persons or parties to install apps; and not download apps from third-party app stores.

MORE: Best AR Apps for iOS (So Far)

Most users, and even many security experts, consider the software installed on a smartphone to be the "app." But just as important to many apps' functions is what happens on developers' back-end servers, which do much of the processing and authorization for the client-device apps.

"In reality, we can regard the server as the more important component," the report states. "It is where information is stored and processed. The server is also responsible for synchronizing user data between devices."

A whopping 86% of the server-side functions Positive Technologies tested were vulnerable to routine cross-site scripting attacks, while 43% either leaked information, failed to properly authorize access, or both.

Taken together, the flaws on both the client side and the server side create a rich environment for attackers.

"Hackers seldom need physical access to a smartphone to steal data," the report says. "Eighty-nine percent of vulnerabilities [found] can be exploited using malware."

It all adds up

Overall, it wasn't one big flaw here or there that reduced a smartphone app's security, the report said. Rather, it was the cumulative result of many smaller errors.

"Risks do not necessarily result from any one particular vulnerability on the client or server side. In many cases, they are the product of several seemingly small deficiencies in various parts of the mobile application," the report said. "Taken together, these oversights can add up to serious consequences."

The Positive Technologies researchers examined eight Android apps and nine iOS apps, as well as the server-side components of seven smartphone apps. (If both the iOS and Android versions of an app were examined, they would likely share the same back-end servers.) The app developers fully cooperated with the analyses, although the apps examined were not named in the report.

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Android Phones
Galaxy S25 Plus held in the hand.
Samsung could delay One UI 7’s release in the US — here’s what we know
Android 16 screen-off fingerprint unlock in Settings menu
Android 16's latest beta lets all Pixel users unlock their phone more easily — here’s how
Galaxy S25 Ultra Now brief
Samsung’s Personal Data Engine is a big addition to the Galaxy S25 — here’s why
Samsung Galaxy S25 Edge next to Galaxy S25 Plus
Samsung Galaxy S25 Edge vs. Galaxy S25 Plus: Everything we know so far
Samsung Galaxy S25 Ultra vs S25 Plus vs S25
Satellite messaging on Google Pixel 9 and Samsung Galaxy S25 just landed on 3 more carriers
back of Iris Pixel 9a
The Google Pixel 9a is lacking one of the Pixel 9’s best safety features — here’s what we know
Latest in News
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 25 (#653)
A first look at Amazon's Fallout TV series coming to Prime Video
‘Fallout’ season 3 plans are reportedly being made — while season 2 is still filming
Surface Laptop 7 from the front
Amazon just gave Surface Laptop 7 a 'frequently returned' label — here's what's going on
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
23andME box
23andMe has declared bankruptcy — here's how to delete your data now