threat-intel
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
High
Summary
Researchers at Wake Forest University discovered that nearly two-thirds (282 out of 444) of AI chatbot apps for iOS exposed API keys and open access to AI proxy services through network traffic. This vulnerability, dubbed "LLMjacking," allowed attackers to utilize developer accounts for free AI usage, potentially incurring significant costs. Despite warnings from the researchers three months prior, only a small percentage of developers had addressed the issue, highlighting a persistent security oversight within the AI app ecosystem.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
