Developer Warns That Granting iPhone Camera Permissions Allows Apps to Secretly Capture You

Following the demonstration of a phishing attack that used Apple-style password requests to get into an iPhone user's Apple ID account, developer Felix Krause this week has detailed another proof-of-concept project, this time focused on the iPhone's cameras.

Krause warned that any time you grant an app permission to access your iPhone's front and back cameras, the app can secretly take pictures and videos of you as long as it's running in the foreground (via Motherboard).


Similar to his previous blog post, Krause's camera privacy project isn't about disclosing a new iOS bug, but more about warning users that this kind of privacy violation is possible within iOS. Many apps regularly request permission to the camera in iOS, allowing users to post photos from their Camera Roll, take a picture within the app without leaving it, and more.

Krause explained that with these permissions granted to a malicious app, the iPhone's front and back cameras can be turned on when that app is running. From there it could record content, upload it online, and even run real-time facial recognition software to detect emotions, all without indicating that your iPhone is recording you or your surroundings.

Image via Felix Krause

Krause created a demo called watch.user to further emphasize his point, creating a fake social network app that tracks the user. As you browse, Krause explained, "you'll suddenly see pictures of yourself, taken a few seconds ago while you scrolled through the feed." In the image above, he explained that with a vision framework in iOS 11 a developer could even map someone's face to track their expressions, and Krause's mapping software displayed a corresponding emoji as a further proof of concept.

The developer said that there are "only a few things you can do" to potentially prevent this from happening, including purchasing camera covers to place over your iPhone's lenses. Otherwise, you have to revoke camera access for all apps -- which would greatly hinder the usefulness of many apps -- and instead always use Apple's built-in Camera app.


Krause reported the issue to Apple, and mentioned a few ways it could be potentially addressed:

- Offer a way to grant temporary access to the camera (e.g. to take and share one picture with a friend on a messaging app), related to detect.location.

- Show an icon in the status bar that the camera is active, and force the status bar to be visible whenever an app accesses the camera

- Add an LED to the iPhone’s camera (both sides) that can’t be worked around by sandboxed apps, which is the elegant solution that the MacBook uses

To double check which apps have access to your iPhone's cameras and photo library, navigate to the Settings app in iOS, tap Privacy, and there you'll find Photos and Camera. Apps that you've granted access to each will be listed, and you can change settings with toggles or choosing to "Never" allow access. As a point of emphasis, Krause's project isn't a bug or a major security breach you need to worry about, but it is a good reminder to ensure the apps you grant camera access to are trustworthy.

Top Rated Comments

(View all)
Avatar
34 months ago
This is exactly why I parade around in front of my iPhone in the nude ...
Score: 58 Votes (Like | Disagree)
Avatar
34 months ago

This is exactly why I parade around in front of my iPhone in the nude ...

Yes, we know.
Score: 39 Votes (Like | Disagree)
Avatar
34 months ago
Newsflash:

Allowing an app to use the camera will allow the app to the camera !!!!!!!


*doh*

Solution:
Deny such request for any app that doesn't NEED the camera.
If the app asks again -> delete
Score: 25 Votes (Like | Disagree)
Avatar
34 months ago
So the app that was explicitly granted permission to use the camera can use it while you actively use the app? OUTRAGE!

I could see that as an issue if it would be able to still use the camera in the background - but it doesn’t!
So what’s the issue?

And iOS 11 introduced separate permissions for using camera and accessing photos - so apps can be more granular at permissions.
Score: 23 Votes (Like | Disagree)
Avatar
34 months ago
A couple of sarky comments along the lines of "If you grant permission, then duh". The problem is that it is recording covertly, while you are browsing normal content. There's no need to be a dick about it, there are numerous apps out there that you grant camera permission to, kids will use filter apps to edit their pics etc. How about when you're on the can browsing through an Instagram style app viewing content, totally oblivious to the fact that it is recording the whole thing? The ideal solution is the LED that the MacBooks have. Having that tie in with a notification light for the OS would be even better.
Score: 23 Votes (Like | Disagree)
Avatar
34 months ago

This is exactly why I parade around in front of my iPhone in the nude ...

I wonder if these app developers that do such things could go to jail for underage naked photos if one of the many under 18 phone users was nude while using their app.
Score: 15 Votes (Like | Disagree)

Top Stories

Apple Releases macOS Catalina 10.15.5 With Battery Health Management Features, Fix for Finder Freezing

Tuesday May 26, 2020 1:59 pm PDT by
Apple today released macOS Catalina 10.15.5, the fifth update to the macOS Catalina operating system that was released in October 2019. macOS Catalina 10.15.5 comes two months after the launch of macOS Catalina 10.15.4, which introduced Screen Time Communication Limits. macOS Catalina 10.15.5 is a free update that can be downloaded from the Mac App Store using the Update feature in the...

Leaker Shares Details on 'iPhone 13' Camera [Updated]

Wednesday May 27, 2020 4:27 pm PDT by
The next-generation iPhone 12 lineup coming in fall 2020 isn't out yet, but Fudge (@choco_bit), a leaker who sometimes shares information on upcoming Apple devices, today offered up details on what Apple has in store for the 2021 iPhone 13's camera setup. A simple design drawing depicts a device with a four camera array, which Fudge claims will have the following features: 64-megapixel...

Leaker: Apple to Stick With Lightning Over USB-C for 'iPhone 12' Before Going Port-Less Next Year

Tuesday May 26, 2020 2:31 am PDT by
Apple will use a Lightning port instead of USB-C in the upcoming "iPhone 12," but it will be the last major series of Apple's flagship phones to do so, with models set to combine wireless charging and a port-less Smart Connector system for data transfer and syncing in the iPhone "13 series" next year. The above claim comes from occasional Apple leaker and Twitter user "Fudge" (@choco_bit),...

16-Inch MacBook Pro, iPad Pro, and iMac Pro With Mini-LED Displays Again Rumored to Launch in 2021

Tuesday May 26, 2020 5:30 am PDT by
Apple plans to release several higher-end devices with Mini-LED displays in 2021, including a new 12.9-inch iPad Pro in the first quarter, a new 16-inch MacBook Pro in the second quarter, and a new 27-inch iMac in the second half of the year, according to Jeff Pu, an analyst at Chinese research firm GF Securities. This timeframe lines up with one shared by analyst Ming-Chi Kuo, who recently...

Apple Begins Selling Refurbished iPhone XR Models

Thursday May 28, 2020 9:50 pm PDT by
Apple today began selling certified refurbished iPhone XR models in select colors and capacities for the first time in the United States. Refurbished iPhone XR models are priced at a roughly 16 percent discount compared to current pricing on brand-new units, knocking $100–120 off of the regular price. In addition to the 64GB and 128GB capacities matching current brand-new iPhone XR models, ...

Apple Making It Harder to Avoid Nagging macOS Update Notifications

Thursday May 28, 2020 8:13 am PDT by
With the release of macOS Catalina 10.15.5 and related security updates for macOS Mojave and High Sierra earlier this week, Apple is making it more difficult for users to ignore available software updates and remain on their current operating system versions. Included in the release notes for macOS Catalina 10.15.5 is the following:- Major new releases of macOS are no longer hidden when...

HBO Max Now Available on Apple TV and iOS Devices

Wednesday May 27, 2020 2:42 am PDT by
HBO Max launched today, and is now available on Apple TV, iPhone, and iPad. WarnerMedia's new streaming service, which replaces HBO Now, combines HBO content with shows and films from Warner Bros and Turner TV. The service is available as a native app on the ‌Apple TV‌ HD and ‌Apple TV‌ 4K, but second and third-generation ‌Apple TV‌ owners will need to AirPlay HBO Max content...

Powerbeats Pro Debut in Four New Colors: Spring Yellow, Cloud Pink, Lava Red, and Glacier Blue

Friday May 29, 2020 10:00 am PDT by
Following a couple of leaks in recent weeks, Beats today is officially announcing four new colors for its Powerbeats Pro wireless earphones: Spring Yellow, Cloud Pink, Lava Red, and Glacier Blue. The new earphones will go on sale June 9 and sell for the same $249.95 price as the existing color options. Aside from the colors, the new Powerbeats Pro models are otherwise identical to the...

Anker Launches $100 24K Gold-Plated USB-C to Lightning Cable

Wednesday May 27, 2020 12:47 pm PDT by
Anker, a brand normally known for its well-made, affordable accessories for Apple devices, has debuted a new $100 24K gold-plated USB-C to Lightning cable. According to Anker, the cable, which is in the PowerLine+ III family, features a "Special Edition Gold Design" that's "bold yet elegant" with the aforementioned gold-plated cable heads and matching braided gold and black cable. The...

More Photos and Video of Apple's Redesigned Leather Loop Watch Band Surface

Thursday May 28, 2020 10:50 am PDT by
Images of a new version of the Leather Loop that Apple appears to have in development surfaced yesterday, and today, Vietnamese site Tinhte.vn has shared additional photos and videos that give us a clearer picture of what to expect from the new band. The bands come in colors that include red, hot pink, blue, black, and brown, with some of the bands featuring different colored accents at the...