iCloud Was Storing Deleted Safari Browser History for Months, but Apple Fixed the Issue

When clearing Safari browser history, iPhone and iPad users expect all records to be permanently deleted from their devices, but it appears Apple's cross-device browser syncing feature caused iCloud to secretly store browsing history for a much longer period of time ranging from several months to over a year.

iCloud was caught storing deleted browser history by software company Elcomsoft, which develops cracking tools for extracting protected data from iOS devices. Speaking to Forbes, Elcomsoft CEO Vladimir Katalov explained that the company had been able to retrieve "deleted" browser history dating back more than a year.

elcomsoftdeletedbrowserhistory

Deleted browser history pulled from iCloud by Elcomsoft

Apple was keeping deleted browser information in a separate iCloud record called "tombstone," and in a press release announcing updated Phone Breaker software for extracting the stored browsing info, Elcomsoft explains that the data was likely kept as part of an iCloud feature that syncs browsing history across multiple devices and ensures it's deleted from all devices when history is cleared.

The point is that Apple keeps synced Safari browsing history in the cloud for much longer than one, three or four months - even for deleted entries. ElcomSoft researchers were able to access records that've been deleted more than a year ago, which means that deleted records are not actually cleaned up from iCloud.

Forbes tried using the Phone Breaker software created by Elcomsoft and was able to retrieve nearly 7,000 records dating back to November of 2015. Site names, URLs, Google searches, visit counts, and the date and time items were deleted were included. It's not clear why Apple was storing the information for so long, but it appears to have been an oversight related to ensuring information is deleted on all devices once cleared rather than intentional.

Shortly after Forbes and Elcomsoft published their iCloud findings, Elcomsoft noticed previously available records being deleted as part of a server-side fix quietly implemented by Apple. All deleted browser records older than two weeks have been eliminated. From Elcomsoft's blog:

Update: we have informed media about this issue in advance, and they reached Apple for comments. As far as we know, Apple has not responded, but started purging older history records. For what we know, they could be just moving them to other servers, making deleted records inaccessible from the outside; but we never know for sure. Either way, as of right now, for most iCloud accounts we can see history records for the last two weeks only (deleted records for those two weeks are still there though).

Good move, Apple. Still, we would like to get an explanation.

Even before Apple made the server-side fix to make sure deleted browsing history is permanently removed in a timely manner, it was difficult to get ahold of the information. Forensic software like Phone Breaker was required, which doesn't come cheap, and Phone Breaker only works with a user's Apple ID and password, or an authentication token pulled from a user's computer.

In iOS 9.3 and later (and Safari 9.1 and later), Apple also began turning URLs into unreadable hashes instead of plaintext when browser history is deleted, an additional security measure, but Forbes says that didn't stop Elcomsoft's tool from working with the newest versions of Safari.

While Apple now appears to be deleting browsing data at the two week mark (or has made it invisible to tools like Phone Breaker), iCloud users should be aware that their browsing history, including cleared browser history, is stored in iCloud for at least that two week period. Users who are not comfortable with that can easily disable syncing features through the iCloud section of the Settings app. Apple has not commented on Elcomsoft's finding or the apparent server-side fix.

Tag: iCloud

Top Rated Comments

AngerDanger Avatar
94 months ago
Apple was keeping deleted browser information in a separate iCloud recored called "tombstone,"
It's a shame they didn't give it some terribly creepy name… wait.

What's written on your tombstone tends to be whatever is most memorable about you, so the fact that Apple considers your internet history worthy of an epitaph is worrisome.



Attachment Image
Score: 27 Votes (Like | Disagree)
yaxomoxay Avatar
94 months ago
Glad they didn't tell my wife......
Score: 17 Votes (Like | Disagree)
Naraxus Avatar
94 months ago
So the line that Cook would always espouse about Apple caring about user privacy is exposed for bull that it always was.
Score: 12 Votes (Like | Disagree)
maflynn Avatar
94 months ago
What else are you looking for from them, though?
Too many companies seem to hide behind it was a bug excuse when they're caught hanging on to data they probably shouldn't have. For a company that seems to pride itself on privacy, this is rather disappointing.
Score: 11 Votes (Like | Disagree)
iShatMyself Avatar
94 months ago
Glad I never used iCloud.
Score: 8 Votes (Like | Disagree)
slimothy Avatar
94 months ago
This is not good.
Score: 8 Votes (Like | Disagree)

Popular Stories

maxresdefault

Apple Announces 'Let Loose' Event on May 7 Amid Rumors of New iPads

Tuesday April 23, 2024 7:11 am PDT by
Apple has announced it will be holding a special event on Tuesday, May 7 at 7 a.m. Pacific Time (10 a.m. Eastern Time), with a live stream to be available on Apple.com and on YouTube as usual. The event invitation has a tagline of "Let Loose" and shows an artistic render of an Apple Pencil, suggesting that iPads will be a focus of the event. Subscribe to the MacRumors YouTube channel for more ...
Apple Silicon AI Optimized Feature Siri

Apple Releases Open Source AI Models That Run On-Device

Wednesday April 24, 2024 3:39 pm PDT by
Apple today released several open source large language models (LLMs) that are designed to run on-device rather than through cloud servers. Called OpenELM (Open-source Efficient Language Models), the LLMs are available on the Hugging Face Hub, a community for sharing AI code. As outlined in a white paper [PDF], there are eight total OpenELM models, four of which were pre-trained using the...
Apple Vision Pro Dual Loop Band Orange Feature 2

Apple Cuts Vision Pro Shipments as Demand Falls 'Sharply Beyond Expectations'

Tuesday April 23, 2024 9:44 am PDT by
Apple has dropped the number of Vision Pro units that it plans to ship in 2024, going from an expected 700 to 800k units to just 400k to 450k units, according to Apple analyst Ming-Chi Kuo. Orders have been scaled back before the Vision Pro has launched in markets outside of the United States, which Kuo says is a sign that demand in the U.S. has "fallen sharply beyond expectations." As a...
iOS 18 Siri Integrated Feature

iOS 18 Rumored to Add These 10 New Features to Your iPhone

Wednesday April 24, 2024 2:05 pm PDT by
Apple is set to unveil iOS 18 during its WWDC keynote on June 10, so the software update is a little over six weeks away from being announced. Below, we recap rumored features and changes planned for the iPhone with iOS 18. iOS 18 will reportedly be the "biggest" update in the iPhone's history, with new ChatGPT-inspired generative AI features, a more customizable Home Screen, and much more....
iPad And Calculator App Feature

Apple Finally Plans to Release a Calculator App for iPad Later This Year

Tuesday April 23, 2024 9:08 am PDT by
Apple is finally planning a Calculator app for the iPad, over 14 years after launching the device, according to a source familiar with the matter. iPadOS 18 will include a built-in Calculator app for all iPad models that are compatible with the software update, which is expected to be unveiled during the opening keynote of Apple's annual developers conference WWDC on June 10. AppleInsider...