iOS Copy-Paste Data Vulnerable to Snooping by Other Apps, Researchers Claim

Researchers claim that apps on iPhones have unrestricted access to the general pasteboard that can reveal personal information.

Advertisement
By Abhik Sengupta | Updated: 25 February 2020 22:48 IST
Highlights
  • Copy-pasted information on iPhones are allegedly vulnerable
  • Researchers claim this info can be accessed without permission
  • Apple in reply said issue not vulnerable

Photo of iPhone used for representational purpose

When it comes to data privacy and security, Apple has rarely shied away from taking credit for its encryption and security. Even in the tech industry, analysts have time to time lauded the company for its relatively secure operating system when compared to its immediate competitors. But now an alleged flaw in its ecosystem, exposed by two researchers, may allow personal data in Apple's iPad and iPhone devices to be intercepted.

According to Talal Haj Bakry and Tommy Mysk, when a user copies any miscellaneous data, it gets stored on Apple's general pasteboard (commonly known as clipboard). This data temporarily stored to the device's memory can be accessed by all apps, thereby, risks revealing private information such as a user's GPS coordinates, passwords and banking details.

"iOS and iPad operating system apps have unrestricted access to the system-wide general pasteboard," the duo noted in a post published on Monday. They added saying, "A user may unwittingly expose their precise location to apps by simply copying a photo taken by the built-in Camera app to the general pasteboard. Through the GPS coordinates contained in the embedded image properties, any app used by the user after copying such a photo to the pasteboard can read the location information stored in the image properties." 

Advertisement

To illustrate how one can access information, Mysk and Bakry published a video on their blog in which the researchers created a rogue proof-of-concept (PoC) app called KlipboardSpy and an iOS widget named KlipSpyWidget to show how data saved in general pasteboard gets accessed by apps. You can watch the video here:

Advertisement

Bakry and Mysk further reclaimed in their post that they first submitted this article and source code to Apple on January 2, 2020. "After analysing the submission, Apple informed us that [it doesn't] see an issue with this vulnerability," they said. In their research, it was also mentioned that going by Apple's policies, "iOS and iPad operating system are designed to allow apps to read the pasteboard only when apps are active in the foreground". The researchers cautioned that these apps can always access when an app widget is added to Apple's Today View.

In the concluding section of their post, the duo suggested that Apple should not have “unrestricted access to the pasteboard without user's consent," adding, "Alternatively, the operating system can only expose the content of the pasteboard to an app when the user actively performs a paste operation."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Z11 Turbo Design Teased; Specifications Leaked
  2. OnePlus Pad Go 2 Review
  3. Oppo Reno 15 Pro Mini Confirmed to Launch in India Alongside These Models
  4. OnePlus Reportedly Developing New Smartphone for India, Global Markets
  5. Asus VM670KA AiO All-in-One Desktop PC With 27-Inch Display Launched in India
  6. Godfather of AI Yann LeCun Reveals the Name of His New AI Startup
  7. Huawei Nova 15 Series With Kirin Chips, Up To 6,500mAh Batteries Launched
  8. Xiaomi Watch 5, Xiaomi Buds 6 to Launch Alongside Xiaomi 17 Ultra
  9. Kaya-Chan Isn't Scary Soon on OTT: Everything You Need to Know About Streaming, Plot, Cast
  10. Here's When the Redmi Pad 2 Pro 5G Will Launch in India
  1. Yann LeCun Sets Up Advanced Machine Intelligence AI Startup After Announcing Departure From Meta
  2. Nayanam Now Available For Streaming Online: What You Need to Know About This Psychological Thriller Online
  3. Kaya-Chan Isn’t Scary OTT Release Details: Know Where to Watch This Anime Horror-Comedy Series Online
  4. Samsung Galaxy S25 Series Gets One UI 8.5 Beta 2 Update in India With New Improvements, Bug Fixes
  5. Oppo Pad Air 5 Display, Battery Upgrades Confirmed Ahead of December 25 Launch in China
  6. OpenAI Upgrades ChatGPT With Adjustable Personality Traits, Response Styles
  7. Huawei Nova 15 Ultra Launched With 6,500mAh Battery, Kirin 9010S Chip, Nova 15 Pro, Nova 15 Tag Along: Price, Features
  8. Huawei Watch 10th Anniversary Edition With 1.38-inch LTPO 2.0 AMOLED Screen, HarmonyOS 6 Launched: Price, Features
  9. OnePlus Phone Codenamed ‘Volkswagen’ With Snapdragon 8s Gen 4 Chip Tipped to Launch in India, Global Markets
  10. How to Keep Your Free Perplexity Pro on Airtel: New Card Requirement Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.