, , , ,

EU iPhone users—avoid alternative app stores until Apple fixes this

If you're using the newest version of Safari on your smartphone, you may be at risk of tracking. This is the worrying finding of two iOS developers and security researchers.

With the latest iOS update to its web browser, Apple finally accommodated EU antitrust rules by introducing a new way for people in the EU to download alternative app stores. However, the feature comes with “catastrophic security and privacy flaws,” Talal Haj Bakry and Tommy Mysk can reveal.

This isn't the first time the duo unveiled security flaws linked to Apple devices and their applications. In January, they discovered the iPhone X app may be sending unwanted personal data without your knowledge. In 2022, they also reported a data leak occurring when using VPN services on iOS 16.

A flawed Safari URI scheme

Under the Digital Market Act (DMA), Big Tech companies falling in the category of gatekeepers have to follow strict requirements intended to reduce anticompetitive behavior. Apple, for example, must allow alternative app stores on iOS.  

That's exactly why the Big Tech giant introduced what's known as URI scheme in the iOS 17.4 update. This mechanism enables iPhone and iPad users in the EU to install alternative marketplace apps directly from the developers’ websites. 

To make it work, marketplace developers are required to include a HTML button that, when tapped in the Safari app, will launch the alternative distribution app installation link (MarketplaceKit). This is a security safeguard, Apple says, to prevent the marketplace from installing apps without a person’s consent. However, according to researchers, Apple's implementation rather endangers the privacy and security of all iPhone users in the EU looking to use this feature. 

“Apple must have forgotten that this is the web, and developers can actually style HTML buttons to virtually look like anything,” wrote Bakry and Mysk in a blog post

That's a big issue because, as the duo discovered, when Safari invokes the URI scheme, it doesn't check whether the website containing the alternative distribution link actually matches a registered marketplace. Worse still, they found the browser would accept any parameters once invoked—even when the information doesn’t match. Other flaws within this system may enable bad actors to intercept and manipulate third-party requests, too.

“This makes the perfect recipe for a malicious marketplace to be able to track users across different websites. All the malicious marketplace has to do is get approved by Apple,” explained Bakry and Mysk, adding that Apple's review process is notoriously flawed as many scam apps continue to find their way into the provider's official App Store.

According to security researchers, all this makes people using an iPhone in the EU vulnerable to cross-site tracking while opening the door to various injection attacks. See the video below for more technical information on how the URI process and security bugs work in practice.

While flaws in software are not uncommon, Bakry and Mysk argue that the severity of these flaws in both the design and implementation raises concerns about Apple’s entire approach to app sideloading. They believe, in fact, that such a security bug is on Apple to keep insisting on inserting itself between the alternative marketplaces and their users. 

For example, they explained, under the system that the Brave app implemented, the secure browser successfully checks the website's origin and fails to invoke the URI scheme if the URLs don’t match. 

“Surprisingly, Apple finds it more important to check if the scheme call came from an HTML button event than checking for cross-site invocation,” said the researchers. They now urge all iPhone users in the EU to use Brave to avoid being tracked.

In the meantime, as the European Commission just added the iPadOS system to its gatekeeper list, Bakry and Mysk are now planning to evaluate the security of Apple's approach also to app sideloading on iPad devices.

I have contacted Apple about this privacy issue, and I'm still waiting for a comment at the time of writing.

https://www.techradar.com/computing/cyber-security/eu-iphone-usersavoid-alternative-app-stores-until-apple-fixes-this


November 2024
M T W T F S S
 123
45678910
11121314151617
18192021222324
252627282930  

About Us

Welcome to encircle News! We are a cutting-edge technology news company that is dedicated to bringing you the latest and greatest in everything tech. From automobiles to drones, software to hardware, we’ve got you covered.

At encircle News, we believe that technology is more than just a tool, it’s a way of life. And we’re here to help you stay on top of all the latest trends and developments in this ever-evolving field. We know that technology is constantly changing, and that can be overwhelming, but we’re here to make it easy for you to keep up.

We’re a team of tech enthusiasts who are passionate about everything tech and love to share our knowledge with others. We believe that technology should be accessible to everyone, and we’re here to make sure it is. Our mission is to provide you with fun, engaging, and informative content that helps you to understand and embrace the latest technologies.

From the newest cars on the road to the latest drones taking to the skies, we’ve got you covered. We also dive deep into the world of software and hardware, bringing you the latest updates on everything from operating systems to processors.

So whether you’re a tech enthusiast, a business professional, or just someone who wants to stay up-to-date on the latest advancements in technology, encircle News is the place for you. Join us on this exciting journey and be a part of shaping the future.

Podcasts

TWiT 1006: Underwater Alien Civilizations – Bluesky Growth, Tyson Vs. Paul, AI Granny This Week in Tech (Audio)

How Bluesky, Alternative to X and Facebook, Is Handling Explosive Growth Netflix's Live Mike Tyson Vs. Jake Paul Fight Battling Sound & Streaming Glitches In Lead-Up To Main Event Biden Asked Microsoft to "Raise the Bar on Cybersecurity." He May Have Helped Create an Illegal Monopoly. CFPB looks to place Google under federal supervision, setting up clash Apple's Tim Cook Has Ways to Cope With the Looming Trump Tariffs Apple Removes Another RFE/RL App At Request Of Russian Regulator Here's Why I Decided To Buy 'InfoWars' Elon Musk's X Corp. files notice in Alex Jones' Infowars bankruptcy case Spotify's Plans For AI Generated Music, Podcasts, and Recommendations, According To Its Co-President, CTO, and CPO Gustav Söderström This 'AI Granny' Bores Scammers to Tears Congress ponders underwater alien civilizations, human hybrids, and other unexplained stuff In Memoriam: Thomas E. Kurtz, 1928–2024 Host: Leo Laporte Guests: Alex Kantrowitz, Daniel Rubino, and Iain Thomson Download or subscribe to This Week in Tech at https://twit.tv/shows/this-week-in-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit
  1. TWiT 1006: Underwater Alien Civilizations – Bluesky Growth, Tyson Vs. Paul, AI Granny
  2. TWiT 1005: $125,000 in Baguettes – iPod Turns 23, The $1.1M AI Painting, Roblox
  3. TWiT 1004: Embrace Uncertainty – Political Texts, Daylight Saving Time, Digital Ad Market
  4. TWiT 1003: CrabStrike – Delta Sues Crowdstrike, Hospital AI, Surge Pricing
  5. TWiT 1002: Maximum Iceland Scenario – Data Caps, 3rd Party Android Stores, Nuclear Amazon