iCloud Was Storing Deleted Safari Browser History for Months, but Apple Fixed the Issue

When clearing Safari browser history, iPhone and iPad users expect all records to be permanently deleted from their devices, but it appears Apple's cross-device browser syncing feature caused iCloud to secretly store browsing history for a much longer period of time ranging from several months to over a year.

iCloud was caught storing deleted browser history by software company Elcomsoft, which develops cracking tools for extracting protected data from iOS devices. Speaking to Forbes, Elcomsoft CEO Vladimir Katalov explained that the company had been able to retrieve "deleted" browser history dating back more than a year.

elcomsoftdeletedbrowserhistory

Deleted browser history pulled from iCloud by Elcomsoft

Apple was keeping deleted browser information in a separate iCloud record called "tombstone," and in a press release announcing updated Phone Breaker software for extracting the stored browsing info, Elcomsoft explains that the data was likely kept as part of an iCloud feature that syncs browsing history across multiple devices and ensures it's deleted from all devices when history is cleared.

The point is that Apple keeps synced Safari browsing history in the cloud for much longer than one, three or four months - even for deleted entries. ElcomSoft researchers were able to access records that've been deleted more than a year ago, which means that deleted records are not actually cleaned up from iCloud.

Forbes tried using the Phone Breaker software created by Elcomsoft and was able to retrieve nearly 7,000 records dating back to November of 2015. Site names, URLs, Google searches, visit counts, and the date and time items were deleted were included. It's not clear why Apple was storing the information for so long, but it appears to have been an oversight related to ensuring information is deleted on all devices once cleared rather than intentional.

Shortly after Forbes and Elcomsoft published their iCloud findings, Elcomsoft noticed previously available records being deleted as part of a server-side fix quietly implemented by Apple. All deleted browser records older than two weeks have been eliminated. From Elcomsoft's blog:

Update: we have informed media about this issue in advance, and they reached Apple for comments. As far as we know, Apple has not responded, but started purging older history records. For what we know, they could be just moving them to other servers, making deleted records inaccessible from the outside; but we never know for sure. Either way, as of right now, for most iCloud accounts we can see history records for the last two weeks only (deleted records for those two weeks are still there though).

Good move, Apple. Still, we would like to get an explanation.

Even before Apple made the server-side fix to make sure deleted browsing history is permanently removed in a timely manner, it was difficult to get ahold of the information. Forensic software like Phone Breaker was required, which doesn't come cheap, and Phone Breaker only works with a user's Apple ID and password, or an authentication token pulled from a user's computer.

In iOS 9.3 and later (and Safari 9.1 and later), Apple also began turning URLs into unreadable hashes instead of plaintext when browser history is deleted, an additional security measure, but Forbes says that didn't stop Elcomsoft's tool from working with the newest versions of Safari.

While Apple now appears to be deleting browsing data at the two week mark (or has made it invisible to tools like Phone Breaker), iCloud users should be aware that their browsing history, including cleared browser history, is stored in iCloud for at least that two week period. Users who are not comfortable with that can easily disable syncing features through the iCloud section of the Settings app. Apple has not commented on Elcomsoft's finding or the apparent server-side fix.

Tag: iCloud

Top Rated Comments

AngerDanger Avatar
58 months ago
Apple was keeping deleted browser information in a separate iCloud recored called "tombstone,"
It's a shame they didn't give it some terribly creepy name… wait.

What's written on your tombstone tends to be whatever is most memorable about you, so the fact that Apple considers your internet history worthy of an epitaph is worrisome.



Attachment Image
Score: 27 Votes (Like | Disagree)
yaxomoxay Avatar
58 months ago
Glad they didn't tell my wife......
Score: 17 Votes (Like | Disagree)
Naraxus Avatar
58 months ago
So the line that Cook would always espouse about Apple caring about user privacy is exposed for bull that it always was.
Score: 12 Votes (Like | Disagree)
maflynn Avatar
58 months ago
What else are you looking for from them, though?
Too many companies seem to hide behind it was a bug excuse when they're caught hanging on to data they probably shouldn't have. For a company that seems to pride itself on privacy, this is rather disappointing.
Score: 11 Votes (Like | Disagree)
iShatMyself Avatar
58 months ago
Glad I never used iCloud.
Score: 8 Votes (Like | Disagree)
slimothy Avatar
58 months ago
This is not good.
Score: 8 Votes (Like | Disagree)

Top Stories

General Apps Messages

All Three Major U.S. Carriers and Google Adopt Rich Communication Services, But No Sign of Apple Interest

Tuesday July 20, 2021 1:15 pm PDT by
For the last several years, Google has been pushing a new communications protocol called Rich Communication Services, or RCS. RCS is designed to replace SMS, the current text message standard, and it offers support for higher resolution photos and videos, audio messages, bigger file sizes, better encryption, improved group chat, and more. Verizon today announced that it is planning to adopt...
AirPods Pro Beta Firmware

AirPods Pro Beta Firmware Now Available

Wednesday July 21, 2021 6:50 am PDT by
Upcoming AirPods Pro firmware updates are now available to Apple Developer Program members as beta versions. AirPods Pro firmware beta one features FaceTime Spatial Audio and Ambient Noise Reduction. Custom Transparency mode, including Conversation Boost, was initially expected to be included in the beta but appears to have been delayed for a later version. Apple made the announcement...
maxresdefault

Apple Music to Livestream Premiere of Kanye West's New Album 'Donda' on Thursday

Wednesday July 21, 2021 1:49 am PDT by
Apple Music on Thursday will host a global livestream for the premiere of Kanye West's tenth studio album, titled "Donda." The sold-out event will take place at the Mercedes-Benz Stadium in Atlanta, Georgia, and Apple Music's livestream will start at 8:00 p.m. Eastern Time. The livestream was revealed in a Beats Studio Buds ad that aired during the NBA Finals. The ad features U.S. track...
ios wifi settings

Apple Confirms iOS 14.7 Fixes WiFi Bug and Many Other Vulnerabilities

Wednesday July 21, 2021 11:38 am PDT by
Following the release of iPadOS 14.7 this morning, Apple has shared details on the security updates that are included in iOS 14.7, iPadOS 14.7, macOS Big Sur 11.5, watchOS 7.6, and tvOS 14.7, all of which came out this week. Notably, Apple's documentation confirms that the iOS 14.7 and iPadOS 14.7 updates address a WiFi-related vulnerability that could impact iOS devices when joining a...
16 inch macbook pro m2 render

Gurman: Redesigned MacBook Pros to Launch Between September and November

Sunday July 18, 2021 7:39 am PDT by
Apple can be expected to release its redesigned 14-inch and 16-inch MacBook Pros sometime between September and November, as part of another packed fall season for new product launches, according to Bloomberg journalist Mark Gurman. In the latest edition of his Power On newsletter, Gurman says that the new MacBook Pros will go into production in the third quarter and can be expected to be...
macOS Malware Feature

Common Windows Malware Can Now Infect Macs

Wednesday July 21, 2021 8:13 am PDT by
A common form of malware on Windows systems has been modified into a new strain called "XLoader" that can also target macOS (via Bleeping Computer). Derived from the Formbook info-stealer for Windows, XLoader is a form of cross-platform malware advertised as a botnet with no dependencies. It is used to steal login credentials, capture screenshots, log keystrokes, and execute malicious files. ...
magsafe battery pack solo

Hands-On With Apple's MagSafe Battery Pack

Tuesday July 20, 2021 11:14 am PDT by
The new MagSafe Battery Pack that Apple debuted this week is arriving to customers starting today and it's also now available for in-store pickup in many Apple retail locations around the world. We snagged one this morning and thought we'd take a look at it to let MacRumors readers know if it's worth the $99 asking price. Subscribe to the MacRumors YouTube channel for more videos. As the name ...
macOS Big Sur Feature Orange

Apple Releases macOS Big Sur 11.5 With Podcast App Updates and Bug Fixes

Wednesday July 21, 2021 10:15 am PDT by
Apple today released macOS Big Sur 11.5, the fifth major update to the macOS Big Sur operating system that launched in November 2020. macOS Big Sur 11.5 comes two months after the release of macOS Big Sur 11.4. The new ‌‌‌‌‌macOS Big Sur‌‌‌‌ 11.5 update can be downloaded for free on all eligible Macs using the Software Update section of System Preferences. macOS Big Sur...
apple tv 4k design green

Apple Releases tvOS 14.7 for Apple TV HD and Apple TV 4K

Monday July 19, 2021 10:04 am PDT by
Apple today released tvOS 14.7, the seventh update to the tvOS 14 operating system that initially debuted in September 2020. tvOS 14.7 comes two months after the launch of the tvOS 14.6 update. tvOS 14.7, which is a free update, can be downloaded over the air through the Settings app on the Apple TV by going to System > Software Update. ‌‌Apple TV‌‌ owners who have automatic software ...
ipad pro m1 feature

Apple Releases iPadOS 14.7 With Apple Card Merging Option, Fix for 3.5mm Headphone Jack to USB-C Adapter Bug

Wednesday July 21, 2021 10:18 am PDT by
Apple today released iPadOS 14.7, marking the seventh major update to the iPadOS operating system that came out in September 2020. Apple already released iOS 14.7 on July 19, but for some reason, delayed the iPadOS 14.7 debut until today. The iPadOS 14.7 update can be downloaded for free and the software is available on all eligible devices over-the-air in the Settings app. To access the new ...