I'm guessing some of you may have already heard about this. For you that haven't, there is a group of researchers that have found a way to break the security for both iOS and OS X keychain and the app sandboxing.
Here is an excerpt from the article,
"Our malicious apps successfully went through Apple’s vetting process and was published on Apple’s Mac app store and iOS app store. "We completely cracked the keychain service - used to store passwords and other credentials for different Apple apps - and sandbox containers on OS X, and also identified new weaknesses within the inter-app communication mechanisms on OS X and iOS which can be used to steal confidential data from Evernote, Facebook and other high-profile apps."
The obvious concern here is the potential of a 'Zero Day' exploit that could open our user's up to their credentials and personal information being compromised. Plus Apple is historically been very tight lipped when it comes to keeping their user base informed on when an update/patch may be coming to address issues such as this. So managing expectations with the leadership at your company may be challenging as well.
I will be opening a ticket with Enterprise Apple Care today, telling them to keep my ticket open and to inform me of any updates here. I'd recommend you all do the same, the more people we have engaging them on this the better.
Link with videos of them showing the hack in action.
http://www.theregister.co.uk/2015/06/17/apple_hosed_boffins_drop_0day_mac_ios_research_blitzkrieg/
Link to their research Paper
https://drive.google.com/file/d/0BxxXk1d3yyuZOFlsdkNMSGswSGs/view?usp=sharing
