Popular iPhone Apps Said to Be Secretly Recording Your Screen, Capturing Sensitive Data in the Process

Advertisement
By Harpreet Singh | Updated: 7 February 2019 13:18 IST
Highlights
  • Several top iPhone apps use session replaying, but don't inform users
  • Some of these apps were sending back data without masking it
  • Sensitive information such as credit card numbers are also recorded

App developers deploy session replaying to see how you interact with their apps, a report claims

A bunch of popular iOS apps may be recording every move you make on their app. These apps have been found to literally record your iPhone screen, without asking for your permission or notifying you about it. According to TechCrunch, several popular iOS apps use Glassbox, an analytics company, to deploy session replaying into their apps. The technology can record every action a user takes on an app, including entering sensitive financial information. None of these apps need user permission to record users' screens.

Popular iOS apps such as Air Canada and Expedia were found to be recording user actions via Glassbox analytics. TechCrunch claims it found several apps from hotels, travel websites, airlines, banks, and others that didn't clarify if they were collecting such data and what they were going to do with it.

The session replay technology enables app developers to record users' every single tap, keyboard entry, button push, etc. However, the data is captured only while a user is within the app.

Advertisement

Apps like Singapore Airlines and Hotels.com also use Glassbox's session replay technology in their apps. These replays allow app developers to record their users' screens and play them back to see how they interacted with the app. On the surface, it seems like a useful developer feature but not all apps were found to be masking users' data, exposing sensitive financial information.

Once a user's session is recorded on the device, it is sent back to the app developer. In the case of Air Canada's iOS app, The App Analyst - a mobile expert cited by TechCrunch - found that the company was clearly exposing passport numbers and credit card information in each session replay being sent back. This means anyone with access to these replays can access sensitive information.

Air Canada had earlier reported that its mobile app had suffered a data breach which affected 20,000 users. The breach leaked passport numbers and other sensitive data.

Advertisement

TechCrunch further added that none of the apps involved in capturing all this data discloses it to their users, even if they're doing it simply for analytics purposes. There may be several other apps that do the same.

While apps that are submitted to the iOS App Store need to carry a privacy policy, TechCrunch didn't find any of the apps the company reviewed mentioning screen recording in their policies. There's literally no way a user can know their screen was being recorded all this time.

Advertisement

App developers use tools from a number of analytics companies and Glassbox isn't the only company that offers session replaying. While collecting user data purely for creating better apps makes sense, it's also important that users are aware how much of their sensitive data could be escaping their device.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Z10R 5G With Dimensity 7360-Turbo Launched After Indian Variant Debuts
  2. Realme GT 8 Pro's Ricoh GR Camera Technology Revealed Ahead of Launch
  3. iQOO 15 Vapour Chamber Cooling System Performance Teased Ahead of Launch
  4. Oppo Reno 15, Reno 15 Pro Key Specifications Tipped Ahead of Launch
  5. Moto G100 (2025) Launched With Snapdragon 7s Gen 2 SoC, 7,000mAh Battery
  6. Nothing Phone 3a Lite Tipped to Launch Soon in These Two Colourways
  7. Google to Invest $15 Billion to Set Up AI-Focused Data Centre in India
  1. JPMorgan Plans to Launch Crypto Asset Trading Services
  2. Nothing Phone Users Can Now Quickly 'Share' Any Content With Essential Space
  3. Samsung Patent Document Hints at 'Self-Healing' Screen for Foldable Phones: Report
  4. Nvidia DGX Spark Supercomputer With Grace Blackwell Chipset to Go on Sale Starting October 15
  5. Bhutan Migrates National ID System to Ethereum Blockchain
  6. OnePlus 15 Battery, Charging Specifications Leaked; Could Launch Soon
  7. Instagram Boosts Teen Safety, Sets PG-13 Content Limits for All New Teen Accounts
  8. Aan Paavam Pollathatu OTT Release Details: Know When and Where to Watch Tamil Movie Online
  9. Mirage to Release on OTT Platforms Soon: Everything You Need to Know About This Malayalam Crime Thriller Film
  10. How To Train Your Dragon Now Streaming on OTT: Know When and Where to Watch the Live-Action Film Online
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.