iPhone apps abuse iOS push notifications to collect user data
ID: 393432f9-1d47-5cbf-af17-ee962bf636bc
STIX ID: report--393432f9-1d47-5cbf-af17-ee962bf636bc
Feed Name: Bleeping Computer
A mobile researcher (Mysk) found that numerous popular iOS apps (e.g., TikTok, Facebook, X, LinkedIn, Bing) abuse push-notification wake-ups to quietly collect and transmit device metadata (uptime, locale, keyboard, memory, battery, storage, model, brightness), enabling fingerprinting and persistent tracking in violation of Apple guidelines. Apple plans to curb this by tightening access to device signal APIs and requiring explicit usage declarations starting in Spring 2024, with non-compliant apps to be rejected; in the interim, users who wish to mitigate risk are advised to disable push notifications entirely.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
