Infosec eggheads find iGiant left EU iOS 17 users open to being tracked around the web
Apple's grudging accommodation of European antitrust rules by allowing third-party app stores on iPhones has left users of its Safari browser exposed to potential web activity tracking.
"Our testing shows that Apple delivered this feature with catastrophic security and privacy flaws," wrote Bakry and Mysk in anA URI scheme is a way of determining how a particular network request gets handled. A website offering an alternative software marketplace can include a button that, when tapped in Safari, launches aprocess on the EU user's iPhone. This process, built into iOS 17.
That designation means the iBiz has been ordered to open its gated community so that European customers can choose third-party app stores and web-based app distribution – also known asAccording to Bakry and Mysk, Apple's URI scheme has three significant failings. First, they say, it fails to check the origin of the website, meaning the aforementioned cross-site tracking is possible.
The limiting factor of this attack is that a marketplace must first be approved by Apple before it can undertake this sort of tracking. At present, not many marketplaces have won approval. We're aware of the B2BThe two security researchers argue that scam apps regularly find their way through Apple's review process, meaning rogue app stores could be allowed through. And they claim the privacy problems arise from Apple wanting to track third-party store usage.
South Africa Latest News, South Africa Headlines
Similar News:You can also read news stories similar to this one that we have collected from other news sources.
WRC Safari Rally: Sublime Rovanpera tames a wild Safari to head Toyota 1-2Kalle Rovanpera delivered a stunning drive to win a gruelling Safari Rally as Toyota claimed its fourth consecutive victory at the famous World Rally Championship event.
Read more »
Singapore infosec boss warns China/West tech split will be bad for interoperabilityWhen you decide not to trust a big chunk of the supply chain, tech (and trade) get harder
Read more »
Japanese government rejects Yahoo! infosec improvement planJust doesn't believe it will sort out the mess that saw data leak from LINE messaging app
Read more »
World's second-largest eyeglass lens-maker blinded by infosec incidentAlso makes components for chips, displays, and hard disks, and has spent four days groping for a fix
Read more »
'I ditched Apple and found a store selling Apple watches for £99 in flash sale'The £99 Apple watch comes in 3 colours - Rose Gold, Silver and Space Grey
Read more »