TechLair

  • Home
  • contact
  • About
  • Privacy Policy

Apps Exploiting Touch ID to Steal Money Booted Out by Apple

Tuesday, December 4, 2018 by Piyush Suthar | Comments

Home News Tech Apps Exploiting Touch ID to Steal Money Booted Out by Apple

In yet another example of fake apps trying to scam users, multiple iOS fitness apps have been removed from the App Store after they were found trying to deceive users and charge a fee ranging from $99 to $139. WeLiveSecurity recently discovered that the apps asked users to use Touch ID to collect health data, but instead, they used the fingerprint data to authenticate a payment.

At least three fake fitness apps were reported by users trying to deceive them into making a payment from their App Store wallet by using Touch ID to pay a high fee. Following the complaints, Apple has removed ‘Heart Rate Monitor’, ‘Fitness Balance’ and ‘Calories Tracker’, all of which were trying to steal money from users using the same method.

Multiple users have reported the incidents of scammy health and fitness apps trying to charge them an exorbitant fee for using the service on Reddit. But the worst part is that many have already fallen for the trick because the payment authentication message pops-up when their finger is on the Touch ID sensor for heart rate measurement or collecting any other vital information.

The hack is quite simple and takes advantage of the fact that a large number of users utilize Touch ID for authenticating a payment. Moreover, the fast authentication speed makes it more convenient for the fraudsters to send a payment confirmation pop-up, and before users can completely process what is happening, the payment has already been completed using their fingerprint data.

To make the scammy fitness apps look legitimate, the fraudsters posted fake reviews of the fitness apps raving about its capabilities and giving it a 5-star rating on the App Store. Victims who contacted the app’s developers got a simple reply that it was due to a bug and will soon be fixed via an update. But the good news is that users can prevent getting scammed by disabling Touch ID payments for iTunes and the App Store.




Authored by Piyush Suthar
Pro Blogger


Follow me on Twitter, Facebook, Google+, YouTube.

Load comments
  • Newer Post
  • Home
  • Older Post
  • techlair
    Over 1,500+ Readers

    Get fresh content from TechLair

    brand222 facebook brand2 envelope-o

    BEST OF TechLair

    Apple Lifts Restrictions on Purchase of iPhones, iPads, MacBooks Outside China
    Facebook pulls post by Anne Frank Center after seeing only nudity in a photo of the Holocaust
    Ericsson, Jio jointly display 5G enabled connected car and VR driving at IMC 2018
    How I accidentally built a tech startup — without any technological knowledge


    Copyright © 2019 TechLair. All rights reserved.
    Privacy Policy • DMCA • Contact