Home / Vulnerability Database / Swift : Third-party keyboard extensions usage
Swift
Swift : Third-party keyboard extensions usage
Classification
OWASP Mobile Top 10 2014
OWASP Mobile Top 10 2016
OWASP MASVS
HIPAA
CWE
CWE/SANS Top 25 2021
Overview
The application allows third-party keyboard extensions to be installed. The leakage of confidential data is possible.
Keyboard extensions are allowed to read each keystroke made by the user. Third-party keyboards are usually used to facilitate text entry or add additional emojis and they may log what the user enters or even sends to the remote server for processing. Malicious keyboards can be used to act as a keylogger and read each user-entered key to steal confidential data, such as credentials or credit card numbers.
Insecure Data Storage vulnerabilities take the second place in the “OWASP Top 10 2016” mobile application vulnerabilities ranking.
MEDIUM
DerScanner Severity Score
Do you want to fix Swift : Third-party keyboard extensions usage in your application?
See also
Swift
Swift : Nill password
Swift
Swift : Hardcoded salt
Swift
