{"id":38352,"date":"2023-02-01T15:46:10","date_gmt":"2023-02-01T20:46:10","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=38352"},"modified":"2023-02-01T15:56:44","modified_gmt":"2023-02-01T20:56:44","slug":"bypassing-ios-16-2-location-privacy","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2023\/02\/01\/bypassing-ios-16-2-location-privacy\/","title":{"rendered":"Bypassing iOS 16.2 Location Privacy"},"content":{"rendered":"<p><a href=\"https:\/\/notes.ghed.in\/posts\/2023\/ifood-bypassing-ios-privacy-location\/\">Rodrigo Ghedin<\/a>:<\/p>\n<blockquote cite=\"https:\/\/notes.ghed.in\/posts\/2023\/ifood-bypassing-ios-privacy-location\/\"><p>iFood, Brazilian largest food delivering app evaluated at <a href=\"https:\/\/www.bloomberglinea.com\/english\/ifood-hits-54b-valuation-surpasses-colombian-rival-rappi\/\">USD 5.4 billion<\/a>, was accessing his location when not open\/in use, bypassing an iOS setting that restrict an app&rsquo;s access to certain phone&rsquo;s features. Even when the reader completely denied location access to it, iFood&rsquo;s app continued to access his phone&rsquo;s location.<\/p>\n<p>[&#8230;]<\/p>\n<p>An educated guess was revealed by <a href=\"https:\/\/support.apple.com\/en-us\/HT213606\">iOS 16.3 release notes<\/a>, launched on January 23th. Apple mentions a security issue in Maps in that &ldquo;an app may be able to bypass Privacy preferences&rdquo;.<\/p><\/blockquote>\n\n<p>Via <a href=\"https:\/\/pxlnv.com\/linklog\/ifood-privacy\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/ifood-privacy\/\">\n<p>I do not want to spread fear or uncertainty, but it is hard to believe iFood would be the only app interested in using location data even if the user has opted out of it. There were <a href=\"https:\/\/twitter.com\/_r3ggi\/status\/1617596250626609154\">several<\/a> privacy-related bugs fixed in this most recent round of operating system updates.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/daringfireball.net\/linked\/2023\/01\/31\/ifood-ios-location\">John Gruber<\/a>:<\/p>\n<blockquote cite=\"https:\/\/daringfireball.net\/linked\/2023\/01\/31\/ifood-ios-location\">\n<p>If the iFood app was really doing this, why is it still in the App Store? If circumventing location privacy by exploiting a bug doesn&rsquo;t get you kicked out of the store, what does?<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/01\/24\/ios-16-3-and-ipados-16-3\/\">iOS 16.3 and iPadOS 16.3<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/01\/10\/sketchy-chatgpt-app-soars-up-app-store-charts\/\">Sketchy ChatGPT App Soars Up App Store Charts<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/10\/10\/midjourney-scam-app\/\">Midjourney Scam App<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/08\/10\/the-top-pdf-reader-in-the-mac-app-store\/\">The Top PDF Reader in the Mac App Store<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2022\/07\/14\/most-fraudulent-apps-still-on-the-app-store\/\">Most Fraudulent Apps Still on the App Store<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Rodrigo Ghedin: iFood, Brazilian largest food delivering app evaluated at USD 5.4 billion, was accessing his location when not open\/in use, bypassing an iOS setting that restrict an app&rsquo;s access to certain phone&rsquo;s features. Even when the reader completely denied location access to it, iFood&rsquo;s app continued to access his phone&rsquo;s location. [&#8230;] An educated [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2023-02-01T20:46:18Z","apple_news_api_id":"dc31e738-98e4-4971-bc60-bea279a2132b","apple_news_api_modified_at":"2023-02-01T20:46:18Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/A3DHnOJjkSXG8YL6ieaITKw","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[91,131,2095,432,2335,31,2185,26,355,48],"class_list":["post-38352","post","type-post","status-publish","format-standard","hentry","category-technology","tag-appstore","tag-bug","tag-exploit","tag-gps","tag-ifood","tag-ios","tag-ios-16","tag-iosapp","tag-privacy","tag-security"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/38352","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=38352"}],"version-history":[{"count":3,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/38352\/revisions"}],"predecessor-version":[{"id":38359,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/38352\/revisions\/38359"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=38352"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=38352"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=38352"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}