HomeSecurityApple iMessage: Exposes IP address & device details

Apple iMessage: Exposes IP address & device details

Apple may need to fine-tune the link preview feature, which the company added to iMessage in iOS 10 and macOS 10.12, which was released two weeks ago, in September.

According to Ross McKillop, this new feature contains an information leakage bug that allows an attacker to learn an iMessage user's IP address, operating system version, and device details.

Apple iMessage: Exposes IP address & device details

Link previews are the small content cards that appear whenever you type and share a URL in a chat window. IM services like Facebook, Twitter, Skype, or Slack also provide this feature, which can be quite convenient, offering a preview of what the link contains without having to leave the IM app.

For the aforementioned services, every time a user shares a link with a person they are chatting with, the service scans the link, accesses the URL, retrieves the data required for a preview (title page, page description, image thumbnail), and embeds the data into the user's internal chat window , when available.

All these operations are performed by the servers of the instant messaging service and only the server's IP address is exposed when submitting the request to retrieve the link preview content.

McKillop says that this case does not involve iMessage, which executes these queries from the user's device.

In a very likely attack scenario, a threat actor or a spammer could send a victim a link to a website they control.

When the user opens iMessage to view the message, even if they never click on the link and access it, iMessage will connect to the URL automatically and retrieve the necessary preview elements.

The attacker's server will collect personal information for each user to whom the attacker sends a link via iMessage. This data is significant and its exposure could have disastrous consequences.

For example, a nation-state actor could learn the target's IP address and get a general idea of the victim's geographic location, the ISP provider, and even the target's real name.

Furthermore, a spammer could use the information they collect to organize their future attacks and send spam or spear-phishing messages in the user's local language or to refine them for mobile or desktop devices, based on the user's device details exposed by iMessage.

Given that there is no user interaction required to exploit this vulnerability, the attack is insignificant and available to any threat actor. Additionally, iMessage does not have any option that allows users to disable link preview, neither on iOS devices nor macOS.

link-preview-content-card-on-ios-10

McKillop says Apple can fix this issue in two ways. The first is to look for link preview data using its own servers and then place the preview data inside iMessage, just like other instant messaging services.

The second way is smarter and doesn't require Apple to set up additional servers. McKillop says Apple could update iMessage so that link previews are retrieved from the sender's device, and then embedded as metadata within the sent message. In that case, attackers would collect the data on their own devices.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS