Arno-MHL/ios-security-vulnerabilities-swift-objc
iOS Security Vulnerabilities Dataset (Swift & Objective-C) A comprehensive dataset of 27 real-world iOS security vulnerability patterns in Swift and Objective-C, covering all OWASP Mobile Top 10 (2024) categories with vulnerable code, secure fixes, attack scenarios, and detection guidance. π― Purpose This is the first dedicated iOS/Swift/Objective-C security vulnerability dataset on Hugging Face. While existing datasets (TitanVul, DiverseVul, CleanVul) focus onβ¦ See the full description on the dataset page: https://huggingface.co/datasets/Arno-MHL/ios-security-vulnerabilities-swift-objc.
iOS Security Vulnerabilities Dataset (Swift & Objective-C)
A comprehensive dataset of 27 real-world iOS security vulnerability patterns in Swift and Objective-C, covering all OWASP Mobile Top 10 (2024) categories with vulnerable code, secure fixes, attack scenarios, and detection guidance.
π― Purpose
This is the first dedicated iOS/Swift/Objective-C security vulnerability dataset on Hugging Face. While existing datasets (TitanVul, DiverseVul, CleanVul) focus on C/C++/Java/Python, none cover iOS-specific security patterns. This dataset fills that gap.
Use cases:
- π€ Train LLMs to detect iOS security vulnerabilities
- π Security training and education for iOS developers
- π Build static analysis rules for Swift/Objective-C
- π‘οΈ Benchmark code security models on mobile-specific patterns
- π‘ Reference guide for iOS security best practices
π Dataset Statistics
π Schema
Each example contains:
π Vulnerability Categories Covered
OWASP Mobile Top 10 (2024) Coverage
iOS-Specific APIs Covered
- Keychain Services β proper vs improper accessibility settings
- UserDefaults/NSUserDefaults β plaintext storage of secrets
- URLSession/NSURLSession β SSL pinning, certificate validation
- WKWebView β XSS, JavaScript bridges, navigation control
- LocalAuthentication β biometric auth bypass via passcode fallback
- CommonCrypto β MD5, ECB mode, PBKDF2
- CryptoKit β AES-GCM, SymmetricKey, SecureRandom
- Core Data β encrypted storage, file protection
- FileManager β backup exclusion, secure file paths
- App Transport Security β proper ATS configuration
- GCD/Dispatch β thread safety with barriers
- UIPasteboard β clipboard expiration and local-only mode
π Quick Start
from datasets import load_dataset
# Load the dataset
ds = load_dataset("Arno-MHL/ios-security-vulnerabilities-swift-objc")
# Browse examples
for example in ds["train"]:
print(f"[{example['severity']}] {example['cwe_id']}: {example['cwe_name']}")
print(f" Language: {example['language']}")
print(f" OWASP: {example['owasp_mobile']}")
print(f" API Misused: {example['ios_api_misused']}")
print()
# Filter by severity
critical = ds["train"].filter(lambda x: x["severity"] == "CRITICAL")
print(f"Critical vulnerabilities: {len(critical)}")
# Filter by language
swift_only = ds["train"].filter(lambda x: x["language"] == "swift")
objc_only = ds["train"].filter(lambda x: x["language"] == "objective-c")
# Get all CWE-312 (cleartext storage) examples
cleartext = ds["train"].filter(lambda x: x["cwe_id"] == "CWE-312")π Example Entry
{
"id": "ios-m9-001",
"language": "swift",
"cwe_id": "CWE-312",
"cwe_name": "Cleartext Storage of Sensitive Information",
"owasp_mobile": "M9: Insecure Data Storage",
"severity": "HIGH",
"ios_framework": "Foundation",
"ios_api_misused": "UserDefaults",
"vulnerability_description": "Storing user authentication tokens in UserDefaults without encryption...",
"vulnerable_code": "// Full Swift code showing insecure UserDefaults usage...",
"secure_code": "// Full Swift code showing proper Keychain Services usage...",
"attack_scenario": "An attacker extracts an iTunes backup and reads the plist...",
"fix_description": "Use iOS Keychain Services with kSecAttrAccessibleWhenUnlockedThisDeviceOnly...",
"detection_hints": "Look for UserDefaults.standard.set() calls with sensitive key names...",
"references": "OWASP Mobile Top 10 2024 M9, CWE-312"
}ποΈ Methodology
This dataset was constructed following patterns from leading vulnerability dataset research:
- Schema design: Based on SecureCode-web (arXiv:2512.18542)
- Vulnerability taxonomy: OWASP Mobile Top 10 (2024) mapped to iOS-specific CWEs
- Code patterns: Real-world vulnerability patterns documented in iOS security research, CVE databases, and Apple security guidelines
- Quality assurance: Each example includes complete, compilable code (not snippets), realistic attack scenarios, and platform-specific remediation
π License
MIT License
π References
- OWASP Mobile Top 10 (2024)
- Apple Security Documentation
- CWE - Common Weakness Enumeration
- TitanVul Dataset
- SecureCode v2.0
βοΈ Citation
@dataset{ios_security_vulnerabilities_2025,
title={iOS Security Vulnerabilities Dataset (Swift & Objective-C)},
author={Arno-MHL},
year={2025},
url={https://huggingface.co/datasets/Arno-MHL/ios-security-vulnerabilities-swift-objc}
}