In March 2025, Cybernews researchers published an analysis of 156,080 randomly selected iOS apps, around 8% of the App Store, and found that 71% of them leaked at least one hard-coded secret. Across the sample they found more than 815,000 secrets, an average of just over five per app, including API keys, cloud storage credentials and payment processor keys, stored in plain text inside the app packages. Following the trail, they found 836 cloud storage endpoints that needed no authentication at all, exposing 406 terabytes of user files and documents, and 2,218 Firebase databases with misconfigured authentication that leaked 19.8 million records. They also found 19 secret keys for the Stripe payment platform. The researchers noted that Apple does not scan app code for hard-coded secrets before approval, so these credentials passed App Store review. No misuse by attackers has been reported.
Key takeaways
- Cybernews analysed 156,080 iOS apps and found that 71% contained at least one hard-coded secret, over 815,000 in total.
- 836 hard-coded cloud storage endpoints were open without authentication, exposing 406 TB of data.
- 2,218 Firebase instances had misconfigured authentication, leaking 19.8 million records including user session tokens.
- Secrets included 19 Stripe secret keys that could be used to issue payments and refunds, the researchers said.
- The identity lesson: anything shipped inside an app belongs to anyone who downloads it; mobile apps need backend-issued, scoped credentials, not embedded keys.
At a glance
| Organisations | Developers of tens of thousands of iOS apps; Apple App Store; Cybernews (research) |
|---|---|
| When | App versions from 2 to 16 October 2024 analysed; research conducted July 2024 to January 2025; published March 2025 |
| Attacker | None known. Found by Cybernews researchers |
| Entry point | Plain-text secrets embedded in iOS app packages (IPA archives) |
| Identities abused | API keys, cloud storage credentials and endpoints, Firebase endpoints and Stripe secret keys hard-coded in apps |
| Impact | Over 815,000 secrets exposed; 406 TB of data in unauthenticated storage and 19.8 million Firebase records accessible; no confirmed misuse |
| Category | NHI. Incident class: exposure (hard-coded secrets in mobile apps, no confirmed misuse) |
What happened
Cybernews researchers downloaded iOS app versions available between 2 and 16 October 2024 and examined their packages. "Without de-obfuscating or decompiling, researchers found a massive number of plaintext secrets stored in IPA archives," according to the release published by Global Security Mag on 12 March 2025. "The average app's code exposes 5.2 secrets, and 71% of apps leak at least one secret," the researchers noted, as quoted by Malwarebytes.
The team then checked where those secrets led. "Out of 94,240 storage bucket instances found hardcoded in iOS applications (with some apps containing multiple storage bucket endpoints), 836 of these endpoints (0.89%) were accessible without authentication, exposing 406TB of user files, personal data, and documents." In addition, "2,218 Firebase instances (4.34%) had misconfigured authentication, leaking 19.8 million records (33GB of data), including user session tokens and backend analytics." Malwarebytes reported that 78,000 apps exposed cloud storage buckets.
Researcher Aras Nazarovas said, as reported by The Clarion: "Many people believe that iOS apps are more secure and less likely to contain malware. However, our research shows that many apps in the ecosystem contain easily accessible hardcoded credentials." The report found 19 Stripe secret keys, which could let attackers issue fraudulent payments and refunds. It also highlighted that Apple's review "does not scan app code for hardcoded secrets before approving them." Fixing the problem is not simple: revoking a key breaks every installed copy of the app until users update, Nazarovas explained.
Timeline
| Date | Event |
|---|---|
| July 2024 | Cybernews research begins. |
| October 2024 | App versions available from 2 to 16 October are collected for analysis. |
| 12 March 2025 | Findings published via Global Security Mag. |
| 14 March 2025 | Malwarebytes reports the research. |
| 17 March 2025 | The Clarion (Troy Media) reports the research. |
How it happened: the identity attack path
- Secrets embedded in apps. Developers hard-coded API keys, storage credentials and endpoints into app code.
- Apps distributed publicly. Anyone can download an app and read the plain-text strings in its package.
- Backends reachable. Some storage buckets and Firebase databases accepted requests without authentication.
- Data exposed. User files, personal data and session tokens were accessible to anyone who followed the trail.
- Hard to remediate. Rotating keys breaks installed app versions until users update.
Impact
- Exposed secrets: more than 815,000 across the 156,080 apps analysed.
- Exposed data: 406 TB in unauthenticated storage and 19.8 million Firebase records, including session tokens.
- Financial risk: 19 Stripe secret keys that could be used for fraudulent payments or refunds.
- Misuse: none reported.
What this means for NHI governance
A mobile app is a public artefact. Any credential compiled into it is effectively published to every user, and to every attacker who downloads it. App store review does not change that, and neither does obfuscation for long. The secrets found here are non-human identities for backend services, cloud storage and payment platforms, and they are often long-lived because rotating them requires shipping a new app version.
The fix is architectural. Apps should obtain short-lived, user-scoped tokens from a backend after authenticating the user, and any keys that must ship in an app should be restricted to the minimum harmless use. Backend services must enforce authentication rather than relying on obscure URLs. See our API Key Management Guide, Secrets Management Guide and Cloud Workload Identity Guide.
Recommendations
- Never ship secret keys in mobile apps. Use a backend to broker access and issue short-lived tokens. See our API Key Management Guide.
- Scan app builds for secrets before release. Add secret scanning to the mobile CI pipeline. See our Secrets Management Guide.
- Require authentication on every storage and database endpoint. Check cloud bucket and Firebase rules.
- Plan for rotation. Design apps to fetch configuration remotely so keys can be rotated without breaking installed versions. See the Leaked Credential Response Playbook.
- Restrict keys that must be public. Limit publishable keys by app, domain and permission.
Frequently asked questions
How many iOS apps leak secrets?
Cybernews found that 71% of the 156,080 iOS apps it analysed leaked at least one hard-coded secret, with more than 815,000 secrets in total.
What kinds of secrets were found in iOS apps?
API keys, cloud storage credentials and endpoints, Firebase database endpoints and payment keys, including 19 Stripe secret keys.
Were users' data actually exposed?
The researchers found 836 storage endpoints open without authentication, exposing 406 TB of data, and misconfigured Firebase instances leaking 19.8 million records. No misuse by attackers has been reported.
Related NHI Mgmt Group resources
12,000 Secrets in LLM Training Data · ASP.NET Machine Key Attacks 2025 · API Key Management Guide · Secrets Management Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Mobile teams often inherit keys that were never meant to be public. We help teams find secrets in app builds, move to backend-issued tokens and plan rotations that do not break users. See our NHI and AI agent security training.