Longitudinal Analysis of iOS In-App Purchase Implementation Vulnerabilities

  • Izabella C. Melo UFPE
  • Vitoria Pinheiro UFPE
  • Divanilson R. Campelo UFPE

Resumo


In-app purchases are a vital monetization strategy for developers, but improper implementation leads to security vulnerabilities. This paper presents the first longitudinal analysis of the evolution of these vulnerabilities in iOS apps’ in-app purchases. Initially, we manually analyzed 34 native apps and found three main client-side vulnerabilities in 21 of them. Then, using an app-agnostic tool, we tested 100 trending apps and identified vulnerabilities in 30 of them. Two years later, 23 of these apps still had vulnerabilities, and five new ones emerged, showing minimal improvement. These findings underscore the ongoing issues with in-app purchase implementations and highlight the need for iOS developers to strengthen their security practices.

Referências

AloneMonkey (2025). frida-ios-dump. [link] Accessed in Aug, 2025.

Apple (2024). About alternative app marketplaces in the european union. [link] Accessed in Aug, 2025.

Apple (2025a). Agreements and guidelines for Apple developers. [link] Accessed in Aug, 2025.

Apple (2025b). App Store stopped over $9 billion in potentially fraudulent transactions in the last five years. [link] Accessed in Aug, 2025.

Apple (2025c). Apple Security Research Device Program. [link] Accessed in Aug, 2025.

Apple (2025d). Choosing a StoreKit API for in-app purchases. [link] Accessed in Aug, 2025.

Apple (2025e). Persisting a purchase. [link] Accessed in Aug, 2025.

Apple (2025f). Unlocking purchased content. [link] Accessed in Aug, 2025.

Business of Apps (2025). App Revenue Data (2024). [link], Accessed in Aug, 2025.

Cryptic Apps (2025). Hopper Disassembler. [link] Accessed in Aug, 2025.

Egele, M. et al. (2011). PiOS: Detecting privacy leaks in iOS applications. In Proc. NDSS.

Egele, M. et al. (2013). An empirical study of cryptographic misuse in Android applications. In Proc. CCS ’13, pages 73–84.

Foresman, C. (2012). Recent iOS, Mac app crashes linked to botched FairPlay DRM. [link] Accessed in Aug, 2025.

Frida (2025). Frida. [link] Accessed in Aug, 2025.

García, L. and Rodríguez., R. J. (2016). A peek under the hood of iOS malware. In 2016 11th International Conference on Availability, Reliability and Security (ARES), pages 590–598.

iOSGods (2025). Decrypted iOS IPA App Store. [link] Accessed in Aug, 2025.

Kellner, A. et al. (2019). False sense of security: Jailbreak detection in banking apps. In Proc. IEEE EuroS&P, pages 1–14.

Mendes, M. (2025). iOS 26.5 RC sets up support for app sideloading in Brazil. [link] Accessed in May, 2026.

MITRE ATT&CK (2018). Collection. [link], Accessed in Aug, 2025.

Mulliner, C. et al. (2014). Virtualswindle: Automated attack against in-app billing on android. In Proc. ASIA CCS ’14, pages 459–470.

Orikogbo, D. et al. (2016). CRiOS: Toward large-scale iOS application analysis. In Proc. SPSM ’16, pages 33–42.

Promon (2024). App threat report: The state of iOS app security. [link] Accessed in Aug, 2025.

Reaves, B. et al. (2017). Mo(bile) money, mo(bile) problems: Branchless banking applications. ACM Trans. Priv. Secur., 20(3).

Reynaud, D. et al. (2012). FreeMarket: Shopping for free in Android applications. In 19th Annual Network And Distributed System Security Symposium.

Sensor Tower (2022). Mobile market forecast 2022-2026. [link] Accessed in Aug, 2025.

Sensor Tower (2025). State of mobile 2025. [link] Accessed in Aug, 2025.

Shi, S. et al. (2021). Breaking and fixing third-party payment service for mobile apps. In Proc. ACNS 2021.

Theos (2025). Theos. [link] Accessed in Aug, 2025.

und3fy.dev (2025). Decrypt.day. [link] Accessed in Aug, 2025.

Yang, W. et al. (2017). Show me the money! Finding flawed implementations of third-party in-app payment in Android apps. In Proc. NDSS.

Zhou, Y. et al. (2021). Payment-Guard: Detecting fraudulent in-app purchases in iOS system. Neurocomputing, 422:263–276.

ZonD80 (2012). Zond80/in-app-proxy: Apple in-app purchases store emulator for iOS < 6. [link] Accessed in Aug, 2025.

Zuo, C. et al. (2019). Why does your data leak? uncovering the data leakage in cloud from mobile apps. In Proc. IEEE S&P, pages 1296–1310.

Zuo, C. and Lin, Z. (2022). Playing without paying: Detecting vulnerable payment verification in native binaries of unity mobile games. In 31th USENIX Security Symposium (USENIX Security 22).
Publicado
01/09/2026
MELO, Izabella C.; PINHEIRO, Vitoria; CAMPELO, Divanilson R.. Longitudinal Analysis of iOS In-App Purchase Implementation Vulnerabilities. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 722-737. DOI: https://doi.org/10.5753/sbseg.2026.26775.

Artigos mais lidos do(s) mesmo(s) autor(es)

1 2 > >>