HT TECH wants to start sending you push notifications. Click allow to subscribe

Uber app can secretly access your iPhone screen, security researcher reveals

Uber is using a tool that could access the screen of iPhone users, claims a security researcher. The taxi hailing app, however, says the tool was used to deliver a better performance on its Apple Watch app.

By: KUL BHUSHAN
Updated on: Oct 07 2017, 12:16 IST
Uber says that the code was being used to improve experience on its Apple Watch app. (REUTERS)

Uber may have been secretly recording your iPhone screen, even when the app is closed. Will Strafach, a New York-based security researcher, discovered that the taxi hailing app had received a special permission from Apple to access the screen-recording feature. The company, however, rejected the security breach fears, stating the code was installed to improve the experience on Apple Watch version of the app.

It is worth understanding that Apple gives "entitlements", a code to developers for enabling access to key features of an iPhone. Access to the screen-recording feature, however, is not available to all developers. Strafach claims that no other third-party apps except Uber had this special privilege. The permission is known as "com.apple.private.allow-explicit-graphics-priority" and allows developers to access and alter parts iPhone's memory that contains data on pixel and display.

You may be interested in

Mobiles Tablets Laptops
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹115,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Vivo X100 Pro 5G
  • Asteroid Black
  • 16 GB RAM
  • 512 GB Storage
₹89,999
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,999₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹30,990₹51,990
Buy now
35% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,678₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

Strafach told Hindustan Times that the code was not limited by location. This essentially means the app had same access to users' devices in India as well. For now, there is no concrete evidence that Uber actually took advantage of this access. He further said, "It looks like Uber was the only app allowed to do this."

Also read: Looking for a smartphone? To check mobile finder click here.

"My surprise was in the fact that this entitlement was granted to help them work around a performance issue and I am not yet clear if Apple had a security review to make sure they fully understood what new access they granted to Uber," Strafach added.

Uber, in the meanwhile, said that it has now removed the API (application program interface) from the app.

"It's not connected to anything else in our current codebase and the diff [sic] to remove it is already being pushed into production. This API would allow maps to render on your phone in the background and then be sent to your Apple Watch," an Uber spokesperson is quoted as saying by Cnet.

"Subsequent updates to Apple Watch and our app removed this dependency, so we're removing the API completely," added the spokesperson.

Even though Uber claims it hasn't been accessing users' sensitive data, such features could put users' security at high risk. Luca Todesco, a security expert, told Zdnet that it was tantamount to giving keylogging ability to apps. Once it is breached, any hacker could get access to users' iPhone screens.

"This move by Uber and Apple has opened up its users to a massive privacy risk. Even if Uber doesn't have any ulterior motive and the special 'entitlement' is only for rendering the maps, malicious hackers if gain access to the internal controls in Uber could spy on users at mass," said Ankush Johar, Director at HumanFirewall.io, a cyber security company.

"Millions of users use the application on Apple's iOS and this access could be exploited gravely if in wrong hands. If a state-sponsored hacker gains access to this feature, it could give a spying agency whether governmental or private, complete access to the targets daily activities including precise location, complete conversations on even the most encrypted channels and all secure passwords that the target is using," he added.

What makes the new revelation more serious is Uber's poor record on maintaining user privacy. The company was earlier this year found using software to track location of drivers of rival company, Lyft, in the US. The software, known as Hell, allowed Uber to gather information including location, rides availability and even drivers' record on whether they previously worked with Uber, reported TheInformation.

In April this year, Apple CEO Tim Cook had warned Uber for violating Apple's guidelines. He even threatened to remove the app from the Apple App Store altogether. Uber was reportedly caught tracking iPhones even after the app was removed from the device.

It's surprising that despite Uber's dismal record on users' privacy, Apple allowed the company to have the special treatment. Apple is yet to respond to the report.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 06 Oct, 14:07 IST

Sale

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
11% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹79,800₹89,900
Buy now
3% OFF
Samsung Galaxy Z Fold5
  • Icy Blue
  • 12 GB RAM
  • 256 GB Storage
₹154,999₹159,999
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
20% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹86,999₹108,699
Buy now
28% OFF
realme Pad 2 WiFi
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
36% OFF
Infinix INBook X1 Pro Laptop
  • Black
  • 8 GB RAM
  • 256 GB SSD
₹44,990₹69,999
Buy now
29% OFF
Asus VivoBook 15 X515JA EJ522TS Laptop
  • Grey
  • 8 GB RAM
  • 512 GB SSD
₹44,689₹62,889
Buy now
34% OFF
Asus ROG Strix G17 G713QM K4215TS Laptop
  • Black
  • 16 GB RAM
  • 1 TB SSD
₹180,990₹272,990
Buy now