iBackDoor: High-Risk Code Hits iOS Apps
fireeye.com
fireeye.com
What they describe is a JavaScript to objc bridge in this library - would would be completely containerized by the embedding application. No, this bridge cannot be used to write outside of the apps container, nor steal keychain credentials outside of the ACLs provided by this application.
If you're embedding a third party library, any of the above could be true. But your user will still be protected to the extent provided by the app security model.
So this is just annoying FUD.
But I don't see how this could be considered a back door since the app developer specifically embedded the library for the functionality it provides. It's more like inviting a vampire to dinner. It can't enter your house if not invited. (And vampires are too "proud" for the servents enter for.). Ok, as a metaphor, this needs work...
When will the list of apps be public?
Also, nowadays it's getting a bit too easy to blame hacking/spying on the Chinese & Russians so you don't want to accuse them until you're absolutely sure. If you're wrong, it's going to look extra bad.