daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ios-app-extensions.md (4058B)


      1 ---
      2 title: "iOS App Extensions"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/ios-pentesting/ios-app-extensions.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/ios-pentesting/ios-app-extensions.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # iOS App Extensions
     14 
     15 App extensions enhance the functionality of apps by allowing them to interact with other apps or the system, providing custom features or content. These extensions include:
     16 
     17 - **Custom Keyboard**: Offers a unique keyboard across all apps, replacing the default iOS keyboard.
     18 - **Share**: Enables sharing to social networks or with others directly.
     19 - **Widgets**: Modern widgets use WidgetKit. Legacy Today extensions may still appear in older applications and remain relevant during assessment.<sup>[[3]](#references)</sup>
     20 
     21 When a user engages with these extensions, such as sharing text from a host app, the extension processes this input within its context, leveraging the shared information to perform its task, as detailed in Apple's documentation.<sup>[[1]](#references)</sup>
     22 
     23 ### **Security Considerations**
     24 
     25 Key security aspects include:<sup>[[1]](#references)</sup>
     26 
     27 - Extensions and their containing apps communicate via inter-process communication, not directly.
     28 - A legacy **Today widget** can request that the system open its containing app through its extension context; do not generalize this behavior to every extension point.
     29 - Shared data access is allowed within a private container, but direct access is restricted.
     30 - Certain APIs, including HealthKit, are off-limits to app extensions, which also cannot start long-running tasks, access the camera, or microphone, except for iMessage extensions.
     31 
     32 ### Static Analysis
     33 
     34 #### **Identifying App Extensions**
     35 
     36 To find app extensions in source code, search for `NSExtensionPointIdentifier` in Xcode or inspect the app bundle for `.appex` files indicating extensions. Without source code, use grep or SSH to locate these identifiers within the app bundle.<sup>[[1]](#references)[[2]](#references)</sup>
     37 
     38 #### **Supported Data Types**
     39 
     40 Check the `Info.plist` file of an extension for `NSExtensionActivationRule` to identify supported data types. This setup ensures only compatible data types trigger the extension in host apps.<sup>[[1]](#references)[[2]](#references)</sup>
     41 
     42 #### **Data Sharing**
     43 
     44 Data sharing between a containing app and its extension normally uses an App Group container. Shared preferences can use `UserDefaults(suiteName:)` (`NSUserDefaults` in Objective-C), while files and databases use the group container URL. Background `URLSession` transfers initiated by an extension also require a shared container configured on the session.<sup>[[1]](#references)[[2]](#references)</sup>
     45 
     46 #### **Restricting Extensions**
     47 
     48 Apps can restrict certain extension types, particularly custom keyboards, ensuring sensitive data handling aligns with security protocols.<sup>[[1]](#references)[[2]](#references)</sup>
     49 
     50 ### Dynamic Analysis
     51 
     52 Dynamic analysis involves:<sup>[[1]](#references)[[2]](#references)</sup>
     53 
     54 - **Inspecting Shared Items**: Hook into `NSExtensionContext - inputItems` to see shared data types and origins.
     55 - **Identifying Extensions**: Discover which extensions process your data by observing internal mechanisms, like `NSXPCConnection`.
     56 
     57 Tools like `frida-trace` can aid in understanding the underlying processes, especially for those interested in the technical details of inter-process communication.
     58 
     59 ## References
     60 
     61 - [1] [MASTG-KNOW-0082: App Extensions - OWASP MASTG](https://mas.owasp.org/MASTG-KNOW-0082/)
     62 - [2] [MASTG-TEST-0072: Testing App Extensions - OWASP MASTG](https://mas.owasp.org/MASTG/tests/ios/MASVS-PLATFORM/MASTG-TEST-0072/)
     63 - [3] [Apple — App Extension Programming Guide: Today widgets](https://developer.apple.com/library/archive/documentation/General/Conceptual/ExtensibilityPG/Today.html)