Team Ai
Datasetpublic

Arno-MHL/ios-security-vulnerabilities-swift-objc

iOS Security Vulnerabilities Dataset (Swift & Objective-C) A comprehensive dataset of 27 real-world iOS security vulnerability patterns in Swift and Objective-C, covering all OWASP Mobile Top 10 (2024) categories with vulnerable code, secure fixes, attack scenarios, and detection guidance. 🎯 Purpose This is the first dedicated iOS/Swift/Objective-C security vulnerability dataset on Hugging Face. While existing datasets (TitanVul, DiverseVul, CleanVul) focus on… See the full description on the dataset page: https://huggingface.co/datasets/Arno-MHL/ios-security-vulnerabilities-swift-objc.

sourceHugging Facemitupdated 6mo agoView on Hugging Face
3likes39downloads
Dataset Card

iOS Security Vulnerabilities Dataset (Swift & Objective-C)

A comprehensive dataset of 27 real-world iOS security vulnerability patterns in Swift and Objective-C, covering all OWASP Mobile Top 10 (2024) categories with vulnerable code, secure fixes, attack scenarios, and detection guidance.

🎯 Purpose

This is the first dedicated iOS/Swift/Objective-C security vulnerability dataset on Hugging Face. While existing datasets (TitanVul, DiverseVul, CleanVul) focus on C/C++/Java/Python, none cover iOS-specific security patterns. This dataset fills that gap.

Use cases:

  • β€”πŸ€– Train LLMs to detect iOS security vulnerabilities
  • β€”πŸ“š Security training and education for iOS developers
  • β€”πŸ” Build static analysis rules for Swift/Objective-C
  • β€”πŸ›‘οΈ Benchmark code security models on mobile-specific patterns
  • β€”πŸ’‘ Reference guide for iOS security best practices

πŸ“Š Dataset Statistics

MetricValue
Total examples27
Train split21
Test split6
LanguagesSwift (20), Objective-C (7)
OWASP categoriesAll 10 Mobile Top 10
Unique CWE IDs20
Severity levelsCRITICAL (4), HIGH (15), MEDIUM (8)

πŸ“‹ Schema

Each example contains:

ColumnTypeDescription
idstringUnique identifier (e.g., ios-m9-001)
languagestringswift or objective-c
cwe_idstringCWE identifier (e.g., CWE-312)
cwe_namestringCWE name
owasp_mobilestringOWASP Mobile Top 10 category
severitystringCRITICAL, HIGH, or MEDIUM
ios_frameworkstringiOS framework involved
ios_api_misusedstringSpecific API that's misused
vulnerability_descriptionstringDetailed description of the vulnerability
vulnerable_codestringComplete vulnerable code example
secure_codestringComplete secure fix with best practices
attack_scenariostringReal-world attack description
fix_descriptionstringStep-by-step remediation guide
detection_hintsstringHow to detect this vulnerability in code
referencesstringStandards and documentation references

πŸ” Vulnerability Categories Covered

OWASP Mobile Top 10 (2024) Coverage

#CategoryExamplesKey CWEs
M1Improper Credential Usage2CWE-798 (Hardcoded credentials)
M2Inadequate Supply Chain Security1CWE-829 (Untrusted SDK)
M3Insecure Authentication1CWE-287 (Biometric bypass)
M4Insufficient Input/Output Validation5CWE-79 (XSS), CWE-89 (SQLi), CWE-134 (Format string), CWE-362 (Race condition)
M5Insecure Communication4CWE-295 (Cert validation), CWE-319 (Cleartext), CWE-829 (WebView)
M6Inadequate Privacy Controls3CWE-532 (Log exposure), CWE-200 (Screenshot/clipboard)
M7Insufficient Binary Protections1CWE-693 (Jailbreak detection bypass)
M8Security Misconfiguration2CWE-939 (URL scheme), CWE-272 (Permissions)
M9Insecure Data Storage6CWE-312 (Cleartext storage), CWE-922 (Backup exposure), CWE-522 (Keychain misuse)
M10Insufficient Cryptography2CWE-327 (Broken crypto), CWE-330 (Weak random)

iOS-Specific APIs Covered

  • β€”Keychain Services β€” proper vs improper accessibility settings
  • β€”UserDefaults/NSUserDefaults β€” plaintext storage of secrets
  • β€”URLSession/NSURLSession β€” SSL pinning, certificate validation
  • β€”WKWebView β€” XSS, JavaScript bridges, navigation control
  • β€”LocalAuthentication β€” biometric auth bypass via passcode fallback
  • β€”CommonCrypto β€” MD5, ECB mode, PBKDF2
  • β€”CryptoKit β€” AES-GCM, SymmetricKey, SecureRandom
  • β€”Core Data β€” encrypted storage, file protection
  • β€”FileManager β€” backup exclusion, secure file paths
  • β€”App Transport Security β€” proper ATS configuration
  • β€”GCD/Dispatch β€” thread safety with barriers
  • β€”UIPasteboard β€” clipboard expiration and local-only mode

πŸš€ Quick Start

python
from datasets import load_dataset

# Load the dataset
ds = load_dataset("Arno-MHL/ios-security-vulnerabilities-swift-objc")

# Browse examples
for example in ds["train"]:
    print(f"[{example['severity']}] {example['cwe_id']}: {example['cwe_name']}")
    print(f"  Language: {example['language']}")
    print(f"  OWASP: {example['owasp_mobile']}")
    print(f"  API Misused: {example['ios_api_misused']}")
    print()

# Filter by severity
critical = ds["train"].filter(lambda x: x["severity"] == "CRITICAL")
print(f"Critical vulnerabilities: {len(critical)}")

# Filter by language
swift_only = ds["train"].filter(lambda x: x["language"] == "swift")
objc_only = ds["train"].filter(lambda x: x["language"] == "objective-c")

# Get all CWE-312 (cleartext storage) examples
cleartext = ds["train"].filter(lambda x: x["cwe_id"] == "CWE-312")

πŸ“– Example Entry

json
{
  "id": "ios-m9-001",
  "language": "swift",
  "cwe_id": "CWE-312",
  "cwe_name": "Cleartext Storage of Sensitive Information",
  "owasp_mobile": "M9: Insecure Data Storage",
  "severity": "HIGH",
  "ios_framework": "Foundation",
  "ios_api_misused": "UserDefaults",
  "vulnerability_description": "Storing user authentication tokens in UserDefaults without encryption...",
  "vulnerable_code": "// Full Swift code showing insecure UserDefaults usage...",
  "secure_code": "// Full Swift code showing proper Keychain Services usage...",
  "attack_scenario": "An attacker extracts an iTunes backup and reads the plist...",
  "fix_description": "Use iOS Keychain Services with kSecAttrAccessibleWhenUnlockedThisDeviceOnly...",
  "detection_hints": "Look for UserDefaults.standard.set() calls with sensitive key names...",
  "references": "OWASP Mobile Top 10 2024 M9, CWE-312"
}

πŸ—οΈ Methodology

This dataset was constructed following patterns from leading vulnerability dataset research:

  • β€”Schema design: Based on SecureCode-web (arXiv:2512.18542)
  • β€”Vulnerability taxonomy: OWASP Mobile Top 10 (2024) mapped to iOS-specific CWEs
  • β€”Code patterns: Real-world vulnerability patterns documented in iOS security research, CVE databases, and Apple security guidelines
  • β€”Quality assurance: Each example includes complete, compilable code (not snippets), realistic attack scenarios, and platform-specific remediation

πŸ“„ License

MIT License

πŸ“š References

✏️ Citation

bibtex
@dataset{ios_security_vulnerabilities_2025,
  title={iOS Security Vulnerabilities Dataset (Swift & Objective-C)},
  author={Arno-MHL},
  year={2025},
  url={https://huggingface.co/datasets/Arno-MHL/ios-security-vulnerabilities-swift-objc}
}