Skype for iOS contains an XSS vulnerability that allows attackers steal information.
“Executing arbitrary Javascript code is one thing, but I found that Skype also improperly defines the URI scheme used by the built-in webkit browser for Skype. Usually you will see the scheme set to something like, “about:blank” or “skype-randomtoken”, but in this case it is actually set to “file://”. This gives an attacker access to the users file system, and an attacker can access any file that the application itself would be able to access.”
Source: SUPEREVR SECURITY BLOG
45 Notes