A link sharing feature in iOS versions of the Safari browser allows iPhone, iPad, and iPod Touch users to change their titles when sharing snippets from webpages.
A researcher has expressed concerns that this feature could be used to spread “fake news” that have a broader impact.

What is the feature?
When browsing web pages, such as articles in the Safari web browser on iPhone or iPad, users can select and share a snippet of text from the page, instead of the entire page.
However, the text snippet can also come from a «text input field» that the user can control and edit.
When you share a snippet from a page with other iPhone users via iMessage, the link preview that is generated changes and the original title of the website is not obvious.
In other words, users can type an arbitrary text value into the search bar of news websites and then “share” that text value via iMessage.
The link preview generated by iMessage, as shown below, will falsely give the impression that the text generated by the user is the actual title of the page.

The behavior can be reproduced specifically when the Apple device is inlandscape orientation and when sharing links with iMessage between iPhone users.
Thus, sharing content in this way from iPhone to Android would not result in this behavior.
This “functionality” was mentioned in the past by MacRumours in 2019, which noted that there were some legitimate use cases for this capability.
However, Josh Long, who is the lead security analyst at Intego, believes that beyond some harmless pranks, this feature could have a broader impact if used to spread false information (so-called fake news).
“Currently there is nothing that prevents a user from typing a misleading title or other misleading text into a field and making it part of the page preview”, Long explained on Intego’s blog in 2019.
The issue was disclosed months ago and Apple hasn't fixed it
Even though findings related to this issue were made public as early as 2019, the latest Apple devices continue to ship with this feature enabled.
On November 5, Apple released iOS 14.2, iPadOS 14.2 , and iOS 12.4.9, none of which fixed the Safari bug
We don't know if this feature has actually been exploited on a large scale to conduct activities like public manipulation or election interference , but that doesn't mean the concerns raised by Intego should be ignored
For those interested in trying this feature out for themselves, there is a detailed PoC video on YouTube.
Information source: bleepingcomputer.com
