A look at the OS X and iOS security vulnerabilities that make up XARA and what to do until Apple fixes them
XARA, deconstructed: An in-depth look at OS X and iOS cross-app resource attacks — Does the Indiana University XARA whitepaper make your head hurt?
Context & Ripple Effects
This explainer lands days after Indiana University's XARA whitepaper disclosed cross-app resource attacks affecting both OS X and iOS — a class of bug where one app can reach another app's protected resources because the platforms' sandbox boundaries don't hold. iMore's job here is translation: what the attack actually is, and what users can do in the gap before Apple ships a fix.
The arc matters because this 2015 disclosure sits at the start of a pattern the related coverage keeps confirming: Apple's Safari and OS X zero-day patches tied to NSO's iOS attack chain in 2016, and by 2023 emergency updates fixing 16 zero-days in a single year. Cross-app resource confusion was an early entry in the ledger of Apple platform bugs that outlive their disclosures.
First-order effects
- OS X and iOS users are exposed to cross-app resource attacks — keychain access, container and scheme hijacking — with no vendor patch available yet, so interim mitigations are all they have.
- Apple faces immediate pressure to close the sandbox-boundary gaps the Indiana University team documented across both desktop and mobile at once.
Second-order effects
- Security researchers get a reusable template for auditing how apps trust each other's resources, raising the odds similar findings surface for other apps and platforms.
- Enterprises running mixed Mac and iPhone fleets must weigh whether to restrict inter-app behaviors now or wait for Apple's official fix.
Third-order effects
- If the pattern holds — as the later zero-day cadence suggests — Apple's security posture shifts from periodic releases toward a permanent disclose-then-emergency-patch loop, making interim user guidance a standing part of every disclosure rather than an exception.
The trend: Cross-app resource attacks like XARA mark the start of Apple's shift from scheduled security updates to a continuous emergency-patch cycle driven by researcher disclosures.