HomeSecuritySpotlight exposes personal information of OS X users

Spotlight exposes personal information of OS X users

Spotlight

A privacy vulnerability that could expose private information about the recipient of an email to the sender has been discovered in Spotlight, the search tool across OS X.

Spotlight is designed to show all items on an OS X system, so that the user can quickly find an item.

To improve the search experience, the app also provides previews of certain file types, including emails. When an email message preview is displayed, images available from external sources are also loaded.

Advertisers and phishers often include images in emails to see if the recipient has opened their message, thus confirming that the address is active. By including small photos hosted on their servers, they capture users' machines via emails.

The images they use are one pixel in size, making them invisible to the user. Most email clients, including Apple Mail, can block external content from loading when a user opens a message, specifically to avoid such tracking methods. However, Spotlight does not have such a setting.

When the external element is loaded, the administrator of the server hosting it receives information about the recipient, which would benefit not only advertisers, but also cybercriminals.

Based on the information one can obtain about their victim, an attacker could develop methods that are appropriate for their victim's settings and also know that the user checks their inbox. Furthermore, in a targeted advertisement, the victim's interest in a certain topic is crucial to the success of the campaign.

A method to prevent data leakage is available for OS X and it recommends disabling the display of emails from appearing in the list of search results generated by Spotlight.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS