Research Reveals How iPhone Push Notifications Leak User Data

Security researcher Tommy Mysk has demonstrated that iPhone push notifications are being used by popular apps to covertly send data about the user.

iPhone 12 Security Feature
In a new video outlining the practice, Mysk highlighted how certain iOS apps exploit a feature introduced in iOS 10 that is designed to allow apps to customize push notifications. This feature, initially intended to enable apps to enrich notifications with additional content or decrypt encrypted messages, has seemingly been repurposed by some developers for more secretive activities. According to Mysk's findings, various popular applications, including TikTok, Facebook, Twitter, LinkedIn, and Bing, are using the short background execution time granted for notification customization to send analytics information.

This practice is particularly worrisome because it circumvents the typical restrictions imposed by iOS on background app activities. Apple has always maintained strict control over applications running in the background to protecting user privacy and ensure optimal device performance. However, the push notification feature appears to have unintentionally provided a backdoor for apps to conduct background data transmission.

The type of data being sent includes unique device signals that can be used for fingerprinting and tracking users across different apps. Fingerprinting is a method of collecting specific information about a device, such as its hardware and software configurations, to create a unique identifier for the user. This identifier can then be used to track the user's activities across different applications, which can then be used for various activities such as targeted advertising.

Apple does not permit fingerprinting and will soon require developers to explicitly state why their apps need access to APIs that are often used for fingerprinting. This move is in line with Apple's efforts to strengthen user privacy, such as the introduction of App Tracking Transparency in iOS 14.5, which requires apps to obtain user permission before tracking their activity across other companies' apps and websites.

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Rumored to Use Same Rear Chassis as iPhone 16

Friday July 19, 2024 7:16 am PDT by
Apple will adopt the same rear chassis manufacturing process for the iPhone SE 4 that it is using for the upcoming standard iPhone 16, claims a new rumor coming out of China. According to the Weibo-based leaker "Fixed Focus Digital," the backplate manufacturing process for the iPhone SE 4 is "exactly the same" as the standard model in Apple's upcoming iPhone 16 lineup, which is expected to...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Just Two Months Away: Everything We Know

Monday July 15, 2024 4:44 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
iphone 14 lineup

Cellebrite Unable to Unlock iPhones on iOS 17.4 or Later, Leak Reveals

Thursday July 18, 2024 4:18 am PDT by
Israel-based mobile forensics company Cellebrite is unable to unlock iPhones running iOS 17.4 or later, according to leaked documents verified by 404 Media. The documents provide a rare glimpse into the capabilities of the company's mobile forensics tools and highlight the ongoing security improvements in Apple's latest devices. The leaked "Cellebrite iOS Support Matrix" obtained by 404 Media...
tinypod apple watch

TinyPod Turns Your Apple Watch Into an iPod

Wednesday July 17, 2024 3:18 pm PDT by
If you have an old Apple Watch and you're not sure what to do with it, a new product called TinyPod might be the answer. Priced at $79, the TinyPod is a silicone case with a built-in scroll wheel that houses the Apple Watch chassis. When an Apple Watch is placed inside the TinyPod, the click wheel on the case is able to be used to scroll through the Apple Watch interface. The feature works...
bsod

Crowdstrike Says Global IT Outage Impacting Windows PCs, But Mac and Linux Hosts Not Affected

Friday July 19, 2024 3:12 am PDT by
A widespread system failure is currently affecting numerous Windows devices globally, causing critical boot failures across various industries, including banks, rail networks, airlines, retailers, broadcasters, healthcare, and many more sectors. The issue, manifesting as a Blue Screen of Death (BSOD), is preventing computers from starting up properly and forcing them into continuous recovery...
Apple Watch Series 9

2024 Apple Watch Lineup: Key Changes We're Expecting

Tuesday July 16, 2024 7:59 am PDT by
Apple is seemingly planning a rework of the Apple Watch lineup for 2024, according to a range of reports from over the past year. Here's everything we know so far. Apple is expected to continue to offer three different Apple Watch models in five casing sizes, but the various display sizes will allegedly grow by up to 12% and the casings will get taller. Based on all of the latest rumors,...

Top Rated Comments

idmean Avatar
25 weeks ago

TikTok, Facebook, Twitter, LinkedIn, and Bing
Anyone who values their privacy shouldn't install any of these ever anyhow.
Score: 38 Votes (Like | Disagree)
trainwrecka Avatar
25 weeks ago
Imagine if this was your job at these companies. Employee, I need you to figure out a way to do something the company and the user does not want.

Everyday... your goal is to deceive. Sad life.
Score: 25 Votes (Like | Disagree)
Timo_Existencia Avatar
25 weeks ago
...but hey! Forcing Apple to open up to sideloading and 3rd Party App stores will have zero effect. Right?
Score: 21 Votes (Like | Disagree)
G5isAlive Avatar
25 weeks ago
It’s always a cat and mouse game with the same bad actors.
Score: 16 Votes (Like | Disagree)
Apple Knowledge Navigator Avatar
25 weeks ago
Zuck would sell his own family if it meant getting a little more data.
Score: 12 Votes (Like | Disagree)
Wizard_of_Woz Avatar
25 weeks ago
One of the best decisions I've ever made was deleting the few (anti) social media accounts I had a few years ago. This article highlights reason 4,357,288 to leave social media. To each their own, but social media IMO is nothing but toxic, time wasting garbage. To be fair though, it wasn't as bad when it first started. If I want to see friends or family, I will either drive/fly to see them, they come to see me, or if they are low on funds I will fly them to see me. If I want to talk to someone, I call them. If someone prefers text messages over phone calls, I text them.
Score: 12 Votes (Like | Disagree)