Cyber criminals can use apps to secretly turn on your iPhone's camera at any time: Here's how to protect yourself
- Google engineer Felix Krause has found a loophole in Apple's permission system
- He built an app that silently takes a picture of its user every second
- The malicious app then secretly uploads each photo to the internet
- The only safe way to protect yourself is using camera covers, which can be bought online
Cyber criminals can use iPhone apps to secretly turn on your front or back camera at any time, a security expert has warned.
Google engineer Felix Krause was able to build an app that silently takes a picture of its user every second and then uploads them to the internet.
He said the issues is a 'privacy loophole that can be abused by iOS apps'.
The only safe way to protect yourself from the hack is using camera covers, which can be bought online, though a simple sticky note will suffice.
You can also revoke camera access for all apps and always use the built-in camera app to avoid being caught out.
Scroll down for video
Cyber criminals can use iPhone apps to secretly turn on your front or back camera at any time, a security expert has warned. An engineer was able to build an app that silently takes a picture of its user every second and then secretly uploads them to the internet (stock image)
When an app wants to access your camera, for instance to take a profile photo during set-up, it must first ask for permission.
Once granted, this permission can only be revoked via the settings menu.
Mr Krausse, based in Vienna, Austria, said that once an app is opened, it can take photos and video of the user via either camera at any time.
The iPhone gives no indication that the camera is being used or that the photos are being uploaded to the internet.
'iOS users often grant camera access to an app soon after they download it (e.g., to add an avatar or send a photo),' he wrote in a blog post.
'These apps, like a messaging app or any news-feed-based app, can easily track the users face, take pictures, or live stream the front and back camera, without the user’s consent.'
In Apple's latest operating system, iOS11, permission to access your camera means apps can use the software's facial recognition system.
This means that malicious apps could be used to secretly detect the emotions of users.
The loophole found by Mr Krause is not a bug but simply takes advantage of the way Apple has set up its permission system.
Mr Krause demonstrated this by building a malicious app that took a photo of its user every second and also tapped into a facial recognition programme.
He said other apps could live stream video of users, read their emotions as they scroll through a social network feed, or record what they are saying.
Mr Krausse said Apple should bring in a system of temporary permissions to stop any malicious apps meddling with users' cameras.
These permissions would involve allowing apps to take a picture during the set-up process but taking it away after a short period of time.
The other option would be for Apple to introduce a warning light that lets people know when they are being recorded.
When an app wants to access your camera, for instance to take a profile photo during set-up, it must first ask for permission. But once an app is opened, it can take photos and video of the user via either camera at any time, which cyber criminals could use to their advantage (stock)
The Austrian engineer offered a few solutions for those wishing to protect themselves from the loophole.
'The only real safe way to protect yourself is using camera covers: There is many different covers available, find one that looks nice for you, or use a sticky note (for example),' he wrote.
'You can revoke camera access for all apps, always use the built-in camera app, and use the image picker of each app to select the photo.'
There are few examples of apps being specifically designed to spy on users, but Mr Krausse said it would be easy to hide this behaviour, allowing it to get through Apple's app approval process.
The Austrian engineer works at Google but has said his security research is a hobby and is in no way affiliated to his employers.
Most watched News videos
- Passenger steals all of the tip money from her Uber driver
- Families weep as they wait to discover if loved ones were victims
- Meet Boriska, the boy who says that he was born on MARS
- Piers Morgan furiously responds to the Texas church shooting
- Tiger mauled Russian zookeeper as she was bringing food
- Billionaire Saudi prince arrested in anti-corruption sweep
- Behind the wheels of breaking speed record in a production car
- Trump meets with Japanese Emperor Akihito and Empress Michiko
- Snake dangles from tree with a bat tightly in its grasp
- CPS: 'Evidence proves Scully-Hicks intended to seriously harm Elsie'
- Texas man describes chasing after the Sutherland Springs gunman
- John Lewis teases audiences with potential Christmas ad
- EXCLUSIVE: Humiliation of the Saudi billionaire and his...
- 'Lying in the dirt, playing dead, was terrifying': Boxing...
- Nutella fans go nuts after discovering the company has...
- She's got some front! Shocking moment an Uber passenger...
- EXCLUSIVE: 'I can't believe I gave this up. I've thrown...
- Paradise Papers: Formula 1 champion Lewis Hamilton...
- Rose COULD have saved Jack: Australian schoolgirls prove...
- Married Welsh Labour politician 'takes his own life' days...
- 'Help, I'm sorry!' Distraught driver's screams after...
- 'Reilly has autism, not f***ing leprosy': Heartbroken...
- Harvey Weinstein used ex-Mossad agents and an 'army of...
- 'I'm no hero, my God gave me the skills to do what needed...
- Heartbroken mother pays tribute to her 'metalhead' son,...
- Single mom, 50, is fired from her job at a government...
- Raped and tortured in a Dubai prison: Former managing...
- The incredible moment a snake and a bat fight to the...
- Boy, 17, 'ambushed by two teenagers and disembowelled in...
- Carers of vulnerable woman not seen since 1999 'tied her...