iOS Safari flaw allows deceptive news headlines in Messages
Posted on by Joshua Long
Update: We covered this story again in relation to potential abuses in the 2020 and 2024 U.S. presidential election cycles; see our latest article about this story:
Apple still hasn’t fixed 6-year-old “fake headlines” flaw exploitable for election interference
Thanks to an Apple bug, now it’s easier than ever to create fake news—or at least fake news headlines that appear to come from credible sources.
The editorial team at MacRumors has discovered a bug in Safari for iOS that allows anyone to create deceptive iMessage preview links.
How does the trick work?
The mobile version of Safari (for iPhone, iPad, and iPod touch) allows users to select text from within a Web page before tapping on the Share button, as a means of highlighting a particular portion of a page for the recipient of an iMessage.
However, Apple does not limit the preview text selection to only what the browser received from the Web server, and therein lies the flaw. Users can type something into a page’s search bar (or any other text field), select the text they just typed, tap the browser’s Share button, and then tap the green-and-white Message icon to send it to an iMessage recipient of their choice.
Currently there is nothing to prevent a user from typing a misleading headline or other deceptive text into a field and making it part of the page preview. While MacRumors calls the flaw “fun” and notes that it can easily be exploited as a prank, we feel that all iMessage users should take caution, as the flaw could also potentially be used in more sinister attacks, for example as a means to try to get financial investors to buy or sell stocks in a panic based on false headlines.
Apple has not yet announced plans to mitigate the flaw, but presumably it will be fixed in an upcoming version of iOS. Update: The bug still hasn’t been fixed as of the release of iOS 14.1—more than 20 months after the MacRumors article was published.
The bug does not appear to be present in other iOS browsers we tested, or in Safari for macOS (although the Messages app on macOS will also display misleading previews sent from an iOS device). Additionally, some sites we tested such as the Forbes homepage seemed to be resistant to the page preview bug.
How can I learn more?
We discussed the Safari/iMessage preview bug on episode 71 of the Intego Mac Podcast. Be sure to subscribe to make sure you don’t miss the latest episodes! You’ll also want to subscribe to our e-mail newsletter and keep an eye here on The Mac Security Blog for updates.
You can also follow Intego on your favorite social and media channels: Facebook, Instagram, Twitter, and YouTube (click the 🔔 to get notified about new videos).