PSA: With Camera Permission, iPhone Apps Can Take Pictures And Videos Without You Noticing

This is not a bug, but keep it in mind when a random app asks you for permission to access your camera.

|
Oct 25 2017, 3:30pm

Image: Shutterstock. Composite: Jason Koebler/Motherboard

Whenever you give iPhone apps permission to access your camera, the app can surreptitiously take pictures and videos of you as long as the app is in the foreground, a security researcher warned on Wednesday.

Felix Krause, who recently warned of the danger of malicious iPhone password popups, wrote a blog post as a sort of PSA for iPhone users. To be clear, this is not a bug, but likely intended behavior.

What this means is that even if you don't see the camera "open" in the form of an on-screen viewfinder, an app can still take photos and videos. It is unknown how many apps currently do this, but Krause created a test app as a proof-of-concept.

This behavior is what enables certain "spy" apps like Stealth Cam and Easy Calc - Camera Eye to exist. But even if this behavior is well-known among iOS developers and hardcore users, it's worth remembering that all apps that have camera permission can technically take photos in this way.

"It's something most people have no idea about, as they think the camera is only being used if they see the camera content or a LED is blinking," Krause told Motherboard in a chat over Twitter direct message. Krause currently works at Google, but performed and published this research independently of his work there.

Read more: Turning Off Wi-Fi and Bluetooth in iOS 11's Control Center Doesn't Actually Turn Off Wi-Fi or Bluetooth

What's worse is that, unlike on Mac computers—which show a solid green light when the camera is active—the iPhone has no mechanism to indicate to a user that the camera is on.

"You can get full access to both cameras without indicating that to the user," Krause told me.

To test this functionality, Krause created a custom app called "watch.user" and shared it with me. I installed it on my iPhone and verified that, indeed, the app took pictures of me while I was simply scrolling through it, and it was even running a hidden facial recognition engine.

Krause's app does not upload photos anywhere, nor it stores them in your Photos app, but there's nothing stopping an app from taking pictures and uploading them somewhere without you noticing.

Again, this is not a bug or something you should be too worried about. But it's good to be aware of how much power you're giving apps when you grant them access to your iPhone's cameras.

Apple did not immediately respond to a request for comment.

Got a tip? You can contact this reporter securely on Signal at +1 917 257 1382, OTR chat at lorenzo@jabber.ccc.de, or email lorenzo@motherboard.tv

Get six of our favorite Motherboard stories every day by signing up for our newsletter.