Get Started
- CodeAnt AI
- Control Center
- Pull Request Review
- IDE
- Compliance
- Anti-Patterns
- Code Governance
- Infrastructure Security Database
- Application Security Database
- Apex
- Bash
- C
- Clojure
- Cpp
- Csharp
- Dockerfile
- Elixir
- Fingerprints
- Generic
- Go
- Html
- Java
- Javascript
- Json
- Kotlin
- Ocaml
- Php
- Problem-based-packs
- Python
- Ruby
- Rust
- Scala
- Solidity
- Swift
- Terraform
- Typescript
- Yaml
Keychain-sync
Keychain device sync
The application was observed to store keychain items with the synchronization type kSecAttrSynchronizableAny
meaning that the data will be synced to all of the users other authenticated iOS, iPadOS, and MacOS devices. Unless necessary, the application should avoid over-distribution of sensitive data, as this increases the attack surface for which an attacker may gain access to the data.
Likelihood: LOW
Confidence: MEDIUM
CWE:
- C
- W
- E
- -
- 2
- 7
- 2
- :
-
- L
- e
- a
- s
- t
-
- P
- r
- i
- v
- i
- l
- e
- g
- e
-
- V
- i
- o
- l
- a
- t
- i
- o
- n