Developer Warns That Granting iPhone Camera Permissions Allows Apps to Secretly Capture You

Following the demonstration of a phishing attack that used Apple-style password requests to get into an iPhone user's Apple ID account, developer Felix Krause this week has detailed another proof-of-concept project, this time focused on the iPhone's cameras.

Krause warned that any time you grant an app permission to access your iPhone's front and back cameras, the app can secretly take pictures and videos of you as long as it's running in the foreground (via Motherboard).

iphone8designcameras
Similar to his previous blog post, Krause's camera privacy project isn't about disclosing a new iOS bug, but more about warning users that this kind of privacy violation is possible within iOS. Many apps regularly request permission to the camera in iOS, allowing users to post photos from their Camera Roll, take a picture within the app without leaving it, and more.

Krause explained that with these permissions granted to a malicious app, the iPhone's front and back cameras can be turned on when that app is running. From there it could record content, upload it online, and even run real-time facial recognition software to detect emotions, all without indicating that your iPhone is recording you or your surroundings.

watch user screenshot


Krause created a demo called watch.user to further emphasize his point, creating a fake social network app that tracks the user. As you browse, Krause explained, "you'll suddenly see pictures of yourself, taken a few seconds ago while you scrolled through the feed." In the image above, he explained that with a vision framework in iOS 11 a developer could even map someone's face to track their expressions, and Krause's mapping software displayed a corresponding emoji as a further proof of concept.

The developer said that there are "only a few things you can do" to potentially prevent this from happening, including purchasing camera covers to place over your iPhone's lenses. Otherwise, you have to revoke camera access for all apps -- which would greatly hinder the usefulness of many apps -- and instead always use Apple's built-in Camera app.


Krause reported the issue to Apple, and mentioned a few ways it could be potentially addressed:

- Offer a way to grant temporary access to the camera (e.g. to take and share one picture with a friend on a messaging app), related to detect.location.

- Show an icon in the status bar that the camera is active, and force the status bar to be visible whenever an app accesses the camera

- Add an LED to the iPhone’s camera (both sides) that can’t be worked around by sandboxed apps, which is the elegant solution that the MacBook uses

To double check which apps have access to your iPhone's cameras and photo library, navigate to the Settings app in iOS, tap Privacy, and there you'll find Photos and Camera. Apps that you've granted access to each will be listed, and you can change settings with toggles or choosing to "Never" allow access. As a point of emphasis, Krause's project isn't a bug or a major security breach you need to worry about, but it is a good reminder to ensure the apps you grant camera access to are trustworthy.

Top Rated Comments

D.T. Avatar
52 months ago
This is exactly why I parade around in front of my iPhone in the nude ...
Score: 58 Votes (Like | Disagree)
macguru212 Avatar
52 months ago
This is exactly why I parade around in front of my iPhone in the nude ...
Yes, we know.
Score: 39 Votes (Like | Disagree)
Bug-Creator Avatar
52 months ago
Newsflash:

Allowing an app to use the camera will allow the app to the camera !!!!!!!


*doh*

Solution:
Deny such request for any app that doesn't NEED the camera.
If the app asks again -> delete
Score: 25 Votes (Like | Disagree)
Futurix Avatar
52 months ago
So the app that was explicitly granted permission to use the camera can use it while you actively use the app? OUTRAGE!

I could see that as an issue if it would be able to still use the camera in the background - but it doesn’t!
So what’s the issue?

And iOS 11 introduced separate permissions for using camera and accessing photos - so apps can be more granular at permissions.
Score: 23 Votes (Like | Disagree)
HacKage Avatar
52 months ago
A couple of sarky comments along the lines of "If you grant permission, then duh". The problem is that it is recording covertly, while you are browsing normal content. There's no need to be a dick about it, there are numerous apps out there that you grant camera permission to, kids will use filter apps to edit their pics etc. How about when you're on the can browsing through an Instagram style app viewing content, totally oblivious to the fact that it is recording the whole thing? The ideal solution is the LED that the MacBooks have. Having that tie in with a notification light for the OS would be even better.
Score: 23 Votes (Like | Disagree)
Hater Avatar
52 months ago
This is exactly why I parade around in front of my iPhone in the nude ...
I wonder if these app developers that do such things could go to jail for underage naked photos if one of the many under 18 phone users was nude while using their app.
Score: 15 Votes (Like | Disagree)

Top Stories

studio buds family

Beats Studio Buds Debuting Today With Active Noise Cancellation, Stemless Design, and More for $150

Monday June 14, 2021 8:00 am PDT by
We've seen a lot of teasers about the Beats Studio Buds over the past month since they first showed up in Apple's beta software updates, and today they're finally official. The Beats Studio Buds are available to order today in red, white, and black ahead of a June 24 ship date, and they're priced at $149.99. The Studio Buds are the first Beats-branded earbuds to truly compete with AirPods...
affinity designer contour tool

Serif Updates Affinity Photo, Designer, and Publisher With New Tools and Functions

Thursday February 4, 2021 1:58 am PST by
Serif today announced across-the-board updates for its popular suite of Affinity creative apps, including Affinity Photo, Affinity Designer, and the Apple award-winning Affinity Publisher for Mac, all of which were among the first professional creative suites to be optimized for Apple's new M1 chip. "After another year which saw record numbers of people switching to Affinity, it's exciting to...
maxresdefault

Craig Federighi and Greg Joswiak Discuss iPadOS 15, macOS Monterey, Privacy, Shortcuts on Mac, and More

Saturday June 12, 2021 6:12 am PDT by
As is tradition, Apple executives Craig Federighi and Greg Joswiak joined Daring Fireball's John Gruber in an episode of The Talk Show to discuss several announcements that Apple made over this weeks WWDC, including iPadOS 15, macOS Monterey, and a large focus around privacy. Federighi kicks off the conversation discussing the common architecture, now thanks to Apple silicon, across all of...
M1X MBP Feature

Leaker: Upcoming MacBook Pro to See Price Hike Over Current Model, Equal Performance Across 14 and 16-Inch Sizes

Tuesday August 24, 2021 5:28 am PDT by
The upcoming 14-inch MacBook Pro is set to be more expensive than the current 13-inch MacBook Pro and both the 14 and 16-inch models will offer the same performance, according to the leaker known as "Dylandkt." The leaker shared the information on Twitter, explaining that both of the upcoming MacBook Pro models, expected to come in 14 and 16-inch sizes, will feature the same performance due...
youtube apple tv

YouTube Discontinuing 3rd-Generation Apple TV App, AirPlay Still Available

Wednesday February 3, 2021 3:09 pm PST by
YouTube is planning to stop supporting its YouTube app on the third-generation Apple TV models, where YouTube has long been available as a channel option. A 9to5Mac reader received a message about the upcoming app discontinuation, which is set to take place in March.Starting early March, the YouTube app will no longer be available on Apple TV (3rd generation). You can still watch YouTube on...
General Apps Messages

Android iMessage Competitor Puts Pressure on Apple

Friday July 30, 2021 3:15 am PDT by
Google and the three major U.S. carriers, including Verizon, AT&T, and T-Mobile, will all support a new communications protocol on Android smartphones starting in 2022, a move that puts pressure on Apple to adopt a new cross-platform messaging standard and may present a challenge to iMessage. Verizon recently announced that it is planning to adopt Messages by Google as its default messaging...
YouTube Picture in Picture Feature

YouTube Premium Subscribers Can Now Use iOS Picture-in-Picture: Here's How

Wednesday August 25, 2021 3:55 am PDT by
Google has rolled out picture-in-picture support as an "experimental" feature for YouTube premium subscribers, allowing them to watch video in a small window when the app is closed. If you're a premium YouTube subscriber looking to try out picture-in-picture, follow these steps: Launch a web browser and sign into your YouTube account at YouTube.com. Navigate to www.youtube.com/new. Scroll...
iPhone 13 Dummy Thumbnail 2

Kuo: iPhone 13 to Feature LEO Satellite Communications to Make Calls and Texts Without Cellular Coverage

Sunday August 29, 2021 7:39 am PDT by
The iPhone 13 will feature low earth orbit (LEO) satellite communication connectivity to allow users to make calls and send messages in areas without 4G or 5G coverage, according to the reliable analyst Ming-Chi Kuo. In a note to investors, seen by MacRumors, Kuo explained that the iPhone 13 lineup will feature hardware that is able to connect to LEO satellites. If enabled with the relevant...
twitterqrcode

Twitter Introduces QR Codes for Sharing and Following Accounts

Wednesday November 16, 2016 4:13 pm PST by
Twitter today introduced Snapchat-style QR codes, which are designed to make it easier to find and follow friends on the social network. Each Twitter QR code is unique to an individual Twitter user, so when scanned, it'll bring up the person's account. To access your Twitter QR code, you'll need the official Twitter app for iOS. In the app, go to your profile, tap on the gear icon, and select...
macOS Monterey on MBP Feature

Apple Seeds Sixth Beta of macOS Monterey to Developers

Monday August 30, 2021 1:11 pm PDT by
Apple today seeded the sixth developer beta of macOS Monterey, the newest version of the macOS operating system. The sixth beta comes three weeks after Apple released the fifth macOS Monterey beta. Registered developers can download the beta through the Apple Developer Center and once the appropriate profile is installed, betas will be available through the Software Update mechanism in...