iCloud Was Storing Deleted Safari Browser History for Months, but Apple Fixed the Issue

When clearing Safari browser history, iPhone and iPad users expect all records to be permanently deleted from their devices, but it appears Apple's cross-device browser syncing feature caused iCloud to secretly store browsing history for a much longer period of time ranging from several months to over a year.

iCloud was caught storing deleted browser history by software company Elcomsoft, which develops cracking tools for extracting protected data from iOS devices. Speaking to Forbes, Elcomsoft CEO Vladimir Katalov explained that the company had been able to retrieve "deleted" browser history dating back more than a year.

elcomsoftdeletedbrowserhistory

Deleted browser history pulled from iCloud by Elcomsoft

Apple was keeping deleted browser information in a separate iCloud record called "tombstone," and in a press release announcing updated Phone Breaker software for extracting the stored browsing info, Elcomsoft explains that the data was likely kept as part of an iCloud feature that syncs browsing history across multiple devices and ensures it's deleted from all devices when history is cleared.

The point is that Apple keeps synced Safari browsing history in the cloud for much longer than one, three or four months - even for deleted entries. ElcomSoft researchers were able to access records that've been deleted more than a year ago, which means that deleted records are not actually cleaned up from iCloud.

Forbes tried using the Phone Breaker software created by Elcomsoft and was able to retrieve nearly 7,000 records dating back to November of 2015. Site names, URLs, Google searches, visit counts, and the date and time items were deleted were included. It's not clear why Apple was storing the information for so long, but it appears to have been an oversight related to ensuring information is deleted on all devices once cleared rather than intentional.

Shortly after Forbes and Elcomsoft published their iCloud findings, Elcomsoft noticed previously available records being deleted as part of a server-side fix quietly implemented by Apple. All deleted browser records older than two weeks have been eliminated. From Elcomsoft's blog:

Update: we have informed media about this issue in advance, and they reached Apple for comments. As far as we know, Apple has not responded, but started purging older history records. For what we know, they could be just moving them to other servers, making deleted records inaccessible from the outside; but we never know for sure. Either way, as of right now, for most iCloud accounts we can see history records for the last two weeks only (deleted records for those two weeks are still there though).

Good move, Apple. Still, we would like to get an explanation.

Even before Apple made the server-side fix to make sure deleted browsing history is permanently removed in a timely manner, it was difficult to get ahold of the information. Forensic software like Phone Breaker was required, which doesn't come cheap, and Phone Breaker only works with a user's Apple ID and password, or an authentication token pulled from a user's computer.

In iOS 9.3 and later (and Safari 9.1 and later), Apple also began turning URLs into unreadable hashes instead of plaintext when browser history is deleted, an additional security measure, but Forbes says that didn't stop Elcomsoft's tool from working with the newest versions of Safari.

While Apple now appears to be deleting browsing data at the two week mark (or has made it invisible to tools like Phone Breaker), iCloud users should be aware that their browsing history, including cleared browser history, is stored in iCloud for at least that two week period. Users who are not comfortable with that can easily disable syncing features through the iCloud section of the Settings app. Apple has not commented on Elcomsoft's finding or the apparent server-side fix.

Tag: iCloud

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Rumored to Use Same Rear Chassis as iPhone 16

Friday July 19, 2024 7:16 am PDT by
Apple will adopt the same rear chassis manufacturing process for the iPhone SE 4 that it is using for the upcoming standard iPhone 16, claims a new rumor coming out of China. According to the Weibo-based leaker "Fixed Focus Digital," the backplate manufacturing process for the iPhone SE 4 is "exactly the same" as the standard model in Apple's upcoming iPhone 16 lineup, which is expected to...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Just Two Months Away: Everything We Know

Monday July 15, 2024 4:44 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
bsod

Crowdstrike Says Global IT Outage Impacting Windows PCs, But Mac and Linux Hosts Not Affected

Friday July 19, 2024 3:12 am PDT by
A widespread system failure is currently affecting numerous Windows devices globally, causing critical boot failures across various industries, including banks, rail networks, airlines, retailers, broadcasters, healthcare, and many more sectors. The issue, manifesting as a Blue Screen of Death (BSOD), is preventing computers from starting up properly and forcing them into continuous recovery...
iphone 14 lineup

Cellebrite Unable to Unlock iPhones on iOS 17.4 or Later, Leak Reveals

Thursday July 18, 2024 4:18 am PDT by
Israel-based mobile forensics company Cellebrite is unable to unlock iPhones running iOS 17.4 or later, according to leaked documents verified by 404 Media. The documents provide a rare glimpse into the capabilities of the company's mobile forensics tools and highlight the ongoing security improvements in Apple's latest devices. The leaked "Cellebrite iOS Support Matrix" obtained by 404 Media...
Apple Watch Series 9

2024 Apple Watch Lineup: Key Changes We're Expecting

Tuesday July 16, 2024 7:59 am PDT by
Apple is seemingly planning a rework of the Apple Watch lineup for 2024, according to a range of reports from over the past year. Here's everything we know so far. Apple is expected to continue to offer three different Apple Watch models in five casing sizes, but the various display sizes will allegedly grow by up to 12% and the casings will get taller. Based on all of the latest rumors,...
tinypod apple watch

TinyPod Turns Your Apple Watch Into an iPod

Wednesday July 17, 2024 3:18 pm PDT by
If you have an old Apple Watch and you're not sure what to do with it, a new product called TinyPod might be the answer. Priced at $79, the TinyPod is a silicone case with a built-in scroll wheel that houses the Apple Watch chassis. When an Apple Watch is placed inside the TinyPod, the click wheel on the case is able to be used to scroll through the Apple Watch interface. The feature works...

Top Rated Comments

AngerDanger Avatar
97 months ago
Apple was keeping deleted browser information in a separate iCloud recored called "tombstone,"
It's a shame they didn't give it some terribly creepy name… wait.

What's written on your tombstone tends to be whatever is most memorable about you, so the fact that Apple considers your internet history worthy of an epitaph is worrisome.



Attachment Image
Score: 27 Votes (Like | Disagree)
yaxomoxay Avatar
97 months ago
Glad they didn't tell my wife......
Score: 17 Votes (Like | Disagree)
Naraxus Avatar
97 months ago
So the line that Cook would always espouse about Apple caring about user privacy is exposed for bull that it always was.
Score: 12 Votes (Like | Disagree)
maflynn Avatar
97 months ago
What else are you looking for from them, though?
Too many companies seem to hide behind it was a bug excuse when they're caught hanging on to data they probably shouldn't have. For a company that seems to pride itself on privacy, this is rather disappointing.
Score: 11 Votes (Like | Disagree)
iShatMyself Avatar
97 months ago
Glad I never used iCloud.
Score: 8 Votes (Like | Disagree)
slimothy Avatar
97 months ago
This is not good.
Score: 8 Votes (Like | Disagree)