Have you ever copied a password or perhaps even your credit card number on your iPhone in order to easily paste it onto a website form?
If you have, then it's likely you've just exposed that information to a slew of popular iPhone apps.
App developersTommy Mysk and Talal Haj Bakry recently publishedtheir research uncovering a major vulnerability with the cut-copy-paste feature on Apple iOS devices. The two developers found that Apple provides apps with the ability to read data stored in the system’s clipboard, officially called Pasteboard on iOS devices. Furthermore, they discovered that dozens of popular iPhone and iPad apps access this data every timea user opens them.
“We have investigated many popular apps in the App Store and found that they frequently access the pasteboard without the user being aware,” the developers wrote. “Our investigation confirms that many popular apps read the text content of the pasteboard.”
Apps that could read your copied and cut text, or media on your iOS device include social networking apps like TikTok, Viber, and Weib, as well as gaming applications like Plants vs. Zombies Heroes, PUBG Mobile, and Fruit Ninja. Other apps include live sporting events platform Dazn, ecommerce apps AliExpress and Overstock, and the Hotels.com app.
News applications appeared to lead in accessing this data, however. Some of the apps snooping on your clipboard include ABC News, Accuweather, CBS News, CNBC, The New York Times, Fox News, NPR, The Huffington Post, and Vice News. A full list of the offending apps can be found here.
Mysk and Bakry have also provided a video showing how they discovered the loophole.
It should be noted that there is no proof of anything maliciously being done with this information by the apps or the companies that publish them. This report shows that these applications are simply accessing this data without the users’ awareness or permission.
In February, the same app developer team publishedfindings regarding a similar flaw with the iOS pasteboard. They found that GPS location information was leaking to apps which accessed the clipboard. This would happen if a user had copied an image taken by Apple's default camera app.
According to Mysk and Bakry, Apple informed them that “that they don’t see an issue with this vulnerability.”
With their latest findings, the two are now urging Apple to act.
“It is not clear what the apps do with the data,” they stated. “To prevent apps from exploiting the pasteboard, Apple must act.”
Copyright © 2023 Powered by
TikTok and other popular iOS apps are spying on your iPhone clipboard-啜英咀华网
sitemap
文章
834
浏览
52
获赞
18
Apple unveils iPadOS 14 with search and Apple Pencil upgrades
During its Worldwide Developers Conference on Monday, Apple announced tons of new features for the iNYPD to Google: Quit tracking drunk
The New York Police Department would like Google to stop tracking its Driving While Intoxicated (DWIStolen Tesla leads police on chase after owner finds it with Tesla app
Criminals might want to think twice before stealing a Tesla. A man led police on a chase through RivThese celebrity wax figures are ... really something
We've seen some pretty awful wax figures in our day, but wow, do the ones at the new Dreamland Wax MIt's way too easy to accidentally reply to Instagram Stories
I used to love Instagram Stories.After long days at work, mindlessly tapping through Stories on theApple says it's sorry for FaceTime bug, promises patch to fix it soon
Apple's apology tour continues.The tech giant has issued an official statement apologizing for the mGoogle Hangouts is shutting down for some users in October
Google's Hangouts chat and video conferencing app is going away this year, at least for some users.What to do when you really want to use a group shot on Tinder
Everyone knows a big no-no of Tinder profile photos is group shots. There's no way to tell which cutChunky baby seal born in Japan. Look at him, love him.
There is never a bad time to look at a cute baby animal, so please enjoy this adorable seal.The littTikTok just locked out a ton of users, and people can't take it
When life gives you lemons, make sure to squeeze all that lemon juice straight into your eyes and thPorsche's luxury Macan SUV gets an electric makeover
Porsche is adding more electric vehicles to its luxury lineup, this time transforming its Macan SUVSonic the Hedgehog is now a symbol of the anti
Sonic, SEGA's iconic and adorable racing videogame hedgehog -- who even has a protein named after hiDark Sky mercifully gives Android users 1 more month until shutdown
Dark Sky has been sold to Apple, there's no changing that.However, Android users of the service willMicrosoft workers protest developing HoloLens U.S. military use
Some Microsoft employees feel the company's business entanglements with the U.S. military aren't OK,Very good businessman President Trump uses Texas tragedy to show off his crappy merch
Say what you will about Trump: the man never misses an opportunity to use a national tragedy for per