I've discovered that iMCP exposes its server to the entire local network rather than being restricted to localhost connections only. This creates a significant security vulnerability as sensitive personal data (Messages, Contacts, Calendar, Location, etc.) could potentially be accessed by other devices on the same network.
Current Behavior
According to the documentation and my testing:
- The app and CLI communicate using Bonjour (mDNS) for automatic discovery
- Both advertise a service with type
_mcp._tcp on domain local
- This makes the service discoverable and accessible from any device on the same local network
- Any computer on the same network can connect to the iMCP server running on another machine
Security Implications
This implementation poses several security risks:
- Unauthorized Access: Any device on the local network can discover and potentially connect to the iMCP service
- Data Exposure: Since iMCP has access to highly sensitive data (iMessages, contacts, calendar events, location), this could lead to unauthorized data access
- Man-in-the-Middle Attacks: Bonjour's multicast nature makes it susceptible to MITM attacks
- No Authentication: There appears to be no authentication mechanism between the CLI and the app
This is particularly concerning in:
- Shared networks (offices, co-working spaces, cafes)
- Home networks with guests
- Any environment where not all devices are trusted
Steps to Reproduce
- Install iMCP on Computer A
- Start the iMCP server
- From Computer B on the same network, scan for
_mcp._tcp services
- Computer B can discover and connect to Computer A's iMCP service
Expected Behavior
The server should only be accessible via localhost (127.0.0.1) to ensure that only local processes can connect to it.
Suggested Solutions
- Localhost-only binding: Bind the server to 127.0.0.1 instead of all network interfaces
- Authentication: Implement token-based authentication between CLI and app
- Encryption: Use TLS/SSL for all communications
- Optional network exposure: If network access is needed for legitimate use cases, make it opt-in with clear security warnings
- Access control: Implement a whitelist of allowed client connections
Environment
- macOS version: 15.5 (24F74)
- iMCP version: 1.3.0
Additional Context
While Bonjour is convenient for zero-configuration networking, Apple's own security documentation warns about its risks: "In a hostile environment other mechanisms must be used to ensure the cooperation of participants or to distinguish untrusted Multicast DNS messages" (Apple Support #101889).
Given the sensitive nature of the data iMCP accesses, I believe this should be addressed with high priority.
I've discovered that iMCP exposes its server to the entire local network rather than being restricted to localhost connections only. This creates a significant security vulnerability as sensitive personal data (Messages, Contacts, Calendar, Location, etc.) could potentially be accessed by other devices on the same network.
Current Behavior
According to the documentation and my testing:
_mcp._tcpon domainlocalSecurity Implications
This implementation poses several security risks:
This is particularly concerning in:
Steps to Reproduce
_mcp._tcpservicesExpected Behavior
The server should only be accessible via localhost (127.0.0.1) to ensure that only local processes can connect to it.
Suggested Solutions
Environment
Additional Context
While Bonjour is convenient for zero-configuration networking, Apple's own security documentation warns about its risks: "In a hostile environment other mechanisms must be used to ensure the cooperation of participants or to distinguish untrusted Multicast DNS messages" (Apple Support #101889).
Given the sensitive nature of the data iMCP accesses, I believe this should be addressed with high priority.