
Frankly, it is not easy to launch iOS in Europe after the Digital Markets Law came into force. It is the 17.4 update that introduced it to iPhones in the Old Continent. Among the new features, the feature that allows you to establish an application store other than the App Store is very popular. It’s a seemingly simple idea, but if the discoveries of developers Talal Haj Bakry and Tommy Mysk are to be believed, its implementation seems to have been thought out in a hurry. This only concerns: Safari browsereven private browsing mode.
The summary of their findings is clear: “Our tests show that Apple delivers this feature with outstanding security and privacy flawsS”. What is in question How to manage a request for an alternative shutter installation?. It is based on the use of a program called . MarkertPlaceKit.
Imagine you come to a site that offers to download an app store. You click a button that will trigger the MarkertPlaceKit request. It queries the store server and verifies whether its installation is authenticated. The problem is any site can trigger such a request. This is where the problem starts.
Downloading an alternative store via Safari on iPhone can be dangerous
A site visited from Safari on iPhone by abusing the process Submit the unique identifier generated during the MarkertPlaceKit request to an alternative app store. By working in coordination with several people, the latter can easily track the user from site to sitehe shouldn’t be able to do this.
According to two developers, “cThis is the perfect recipe for a malicious alternative store to track users across different websites. All it has to do is get approved by Apple. History shows that Apple’s review process is deeply flawed, with many fake apps continuing to appear on the App Store“.
Just like its Android equivalent, the Apple app store can actually contain malware. Moreover, two other flaws discoveries leave the door openiPhones infected with malware It mainly targets the MarkertPlaceKit process or the servers of the alternative store. Until Apple fixes these vulnerabilities, Talal Haj Bakry and Tommy Mysk recommend using: Brave. The browser includes an anti-tracking system described here. That’s it already.
Source : mysk.blog
Support our work ❤️
If you enjoyed this article, consider leaving a tip to help us keep publishing great content.
























