iOS 11 Bug Lets Camera QR Code Reader Redirect Users to Malicious Websites: Report

Advertisement
By Ankit Chawla | Updated: 26 March 2018 18:20 IST
Highlights
  • The bug arises as a miscommunication between camera app and Safari
  • URL in notification preview can be different from actual link
  • The vulnerability was reported to Apple in December last year

Another day, another iOS bug discovery. The stock Camera app on iOS 11 was recently updated to automatically detect QR codes and show link previews in case the QR code contains a URL. However, reports have surfaced online that suggest this feature has an apparent bug that can allow people to change the actual URL that is redirected on clicking the link shown in the notification preview.

A report by InfoSec details the new bug that involves creating an unsuspecting hostname such as facebook.com or google.com in the notification preview, while adding a different URL for when it redirects in Safari. For instance, the report uses facebook.com as the front and the actual URL is https://xxx\@facebook.com:443@infosec.rm-it.de/. Scanning the custom QR code will display facebook.com in the notification but clicking on it will open a website not linked with the social media giant. This is said to be because "The URL parser of the camera app has a problem here detecting the hostname in this URL in the same way as Safari does."

Advertisement

This, in turn, is said to cause a miscommunication between the camera app and Safari leading to an evidently major bug. The report claims that Apple was first informed about the bug back on December 23 last year, but as of writing this, the bug has not yet been taken down.

This is not the first instance when iOS 11 has been caught up in a major UI bug incident. Just recently, a privacy vulnerability hit the mobile operating system using which Siri could read out loud notifications from the lock screen, even those that were hidden behind a passcode or biometric verification. Apple has since responded and promised a fix in an upcoming software update.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: QR Codes, iPhone, iPad, Mobiles, Tablets, Apple, Safari, iOS, iOS 11
Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi 17 Max Debuts With 8,000mAh Battery, Leica-Tuned Cameras: See Price
  2. Oppo Enco Air 5 Pro With 12mm Drivers Arrives in India at This Price
  3. Maa Behen OTT Release: When and Where to Watch it Online?
  4. Samsung Galaxy S27 Pro Leak Hints at Major Shake-Up for Galaxy S Lineup
  5. CMF Phone 3 Pro Launch Timeline Leaks as Tipster Reveals Key Specs
  6. HMD Vibe 2 5G Launched in India With 6,000mAh Battery
  7. Vivo X500 Pro Max Might Launch This Year With an 8,000mAh Battery
  1. Oppo Reno 16 Chipset Details Surface via Geekbench Listing; May Feature Dimensity 8500 Chip, 12GB RAM
  2. Scientists Discover New Fuel-Saving Route to the Moon
  3. Madhu Vidhu OTT Release: Where to Watch, Plot, Cast, IMDb Rating, and More
  4. Maa Behen OTT Release Revealed: When and Where to Watch it Online?
  5. LOL: Last One Laughing Germany Season 7 Out on OTT: Know Where to Watch it Online
  6. Warrant: From the World of Vilangu OTT Release Date: When and Where to Watch it Online?
  7. Xiaomi Clip Open-Ear Earbuds Launched With LHDC 5.0 Audio, Up to 38 Hours Total Battery Life: Price, Specifications
  8. Sathi Leelavathi Now Streaming on SunNXT: Everything You Need to Know About Plot, Cast, and More
  9. Xiaomi Smart Band 10 Pro Launched With 1.74-Inch AMOLED Screen, Up to 21 Days Battery Life: Price, Features
  10. Honor Developing Wide-Foldable Phone With Snapdragon 8 Elite Gen 6 SoC, Tipster Claims
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.