Privacy Archives - 9to5Mac Skip to main content

Privacy

See All Stories

Privacy is a growing concern in today’s world. Follow along with all our coverage related to privacy, security, what Apple and other companies are doing to keep your information safe, and what steps you can take to keep your information private.

Security Bite: This old school alias trick will show you who’s selling or leaking your email

plus addressing security privacy email leak gmail outlook icloud mail \

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


In this week’s Security Bite, I’m taking it back over 20 years to the launch of Gmail in 2004–because that’s how long its little-known plus addressing (aliasing) feature has quietly existed. It was originally created to help with filtering and keeping inboxes tidy long before spam became what it is today. Google never really promoted it, so most people still don’t realize it’s a thing. But over the years, it’s become popular among privacy-minded folks to track which online services, subscriptions, etc., are selling email addresses to other companies or leaking them.

Expand Expanding Close

Five VPN apps in the App Store had links to Chinese military

Five VPN apps in the App Store had links to Chinese military | Close-up of a Chinese flag

At least five VPN apps in the App Store were found to have links to the Chinese military, according to a new report today. Three of them have racked up more than a million downloads.

A subsidiary of one of the Chinese companies behind the apps is currently hiring for a role in “monitoring and analysing platform data,” with a familiarity with American culture listed as a job requirement …

Expand Expanding Close

Apple bizarrely fined $162M for App Tracking Transparency after advertisers complained

Apple fined $162M for App Tracking Transparency after advertisers complained | ATT permission screen on iPhone

Apple has been fined $162M by France’s competition regulator for the way App Tracking Transparency is implemented, stating that this is an abuse of the company’s powers.

This bizarre ruling follows a complaint by a group of trade associations representing advertisers who are no longer able to access user data to serve personalized ads …

Expand Expanding Close

Meta AI chatbot rolling out to Europe after privacy delay, with a huge limitation

Meta AI chatbot rolling out to Europe after privacy delay, with a huge limitation | Screengrabs shown

The Meta AI chatbot is finally rolling out to European countries from this week, and will be accessible in Instagram, WhatsApp, Facebook, and Messenger. However, the headline feature of Ray-Ban Meta smart glasses will not be available.

The generative AI feature first launched in the US back in 2023, but privacy concerns were raised when it came to light that the company had been training it on Facebook and Instagram posts since way back in 2007 ….

Expand Expanding Close

iOS 18.4 makes your Safari search history way more visible, for better or worse [U]

Apple wins UK Safari appeal due to gov mess up

Apple has been running a variety of ads over the past year pushing Safari as the privacy-friendly browser choice for iPhone, iPad, and Mac users. But in iOS 18.4 beta 1, there’s a new Safari feature that may accidentally undercut that message—despite offering solid utility.

Update 3/19/25: Added information about a change in iOS 18.4 beta 4 below.

Expand Expanding Close

Smarter Siri delay could be caused by major security concerns, suggests developer

Smarter Siri delay could be caused by major security concerns, suggests developer | Siri logo on iPhone screen

The long wait for a smarter Siri is to get even longer, with some indications that the new features we were originally expecting in iOS 18.4 may now be pushed back to iOS 19.

Apple hasn’t provided any real explanation, but two theories have so far been put forward, and now a developer and data analyst has suggested that security concerns may be a third reason – and by far the biggest problem …

Expand Expanding Close

Apple standing up for Advanced Data Protection is way more important than it seems

Apple standing up for Advanced Data Protection is way more important than it seems | Eyes peering out of the darkness

Apple’s Advanced Data Protection (ADP) is a privacy feature very few people have been using. Non-techies had never heard of it, and even some geeks hadn’t enabled it.

So Apple standing up to the UK government’s attack on ADP might not seem a big deal – but I’d argue that it’s way more important than it might seem, for three reasons …

Expand Expanding Close

Major investigation launched into child protection measures on TikTok, Reddit, and Imgur

Major investigation launched into child protection measures on TikTok, Reddit, and Imgur | App icons seen on an iPhone

The UK’s privacy watchdog has announced a “major investigation” into the child protection measures of three popular apps: TikTok, Reddit, and Imgur.

The Information Commissioner’s Office (ICO) said that it has previously succeeded in bringing about child protection changes on X, Sendit, BeReal, Daily Motion, and Viber …

Expand Expanding Close

Security Bite: Do an app’s privacy labels influence your decision to download it?

app store privacy labels apple

Apple introduced app privacy labels to help people better understand what data an app may collect, including what data is linked to them or used to track them across the web. When released back in 2020, the labels set a precedent in the industry and were a major first step in raising awareness of privacy-invasive apps. It was now easy for users to compare something like Signal, which collects virtually no data at all, and Facebook Messenger, which gobbles up anything it can use to sell advertising or better its services. The feature set out to help users make informed downloads.

However, in recent years, I have seen a growing conversation around whether these entirely self-reported labels located further down on the application’s App Store page still impact the user’s decision before hitting “Get” to install.


9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.

Expand Expanding Close

Apple might be forced to disable a key iPhone privacy feature in France

Apple protects App Tracking Transparency in China

Apple has been under investigation by authorities in France for nearly two years over App Tracking Transparency, a privacy feature that lets iPhone users decide whether their activity can be tracked by advertisers or not. You’ve likely seen many of the ‘Ask App Not to Track’ pop-ups. Now, per a new Reuters report, the case is about to wrap up and looks set to end unfavorably for Apple.

Expand Expanding Close

Brits unmoved by loss of Advanced Data Protection – and Apple needs to change that

Brits unmoved by loss of Advanced Data Protection – and Apple needs to change that | Close-up photo of half-open MacBook shown

In a world in which privacy is a hot-button issue, we might have expected Brits to be outraged that their government was responsible for Apple withdrawing Advanced Data Protection from the UK. In reality, it’s gone largely unremarked.

A new Bloomberg piece suggests that’s because people care far less about privacy than they claim. While I do think there’s some truth to that, it’s not the primary reason …

Expand Expanding Close

Apple currently only able to detect Pegasus spyware in half of infected iPhones

Apple currently only able to detect Pegasus spyware in half of infected iPhones | Close-up of man looking through a spy-hole in a wall

NSO’s Pegasus spyware is one of the most frightening privacy threats an iPhone owner can face. Without you taking any action at all, it’s able to completely take over your phone, accessing almost all of the personal data stored on it, and some versions have been able to activate cameras and microphones.

Pegasus exploits zero-day vulnerabilities – security holes Apple doesn’t yet know about – but the iPhone maker has another way to fight back …

Expand Expanding Close

Apps sold location data for US military and intelligence personnel serving overseas [U]

Apps sold location data for US military and intelligence personnel serving overseas | Soldiers boarding a military transport plane

It was discovered last year that location data for US military and intelligence personnel serving overseas was being sold by a Florida-based data broker, but the source of that sensitive data was unclear at the time.

It’s now been claimed that the data was captured by a variety of mobile apps with revenue-sharing agreements with a Lithuanian ad-tech company, and then resold by an American company …

Expand Expanding Close

Multiple security flaws found in DeepSeek iOS app, including sending unencrypted data

Multiple security flaws have been found in the DeepSeek iOS app, which is still one of the most popular downloads in the App Store after topping the charts when it first launched.

The latest findings are far worse than the previous security failure which exposed chat history and other sensitive information in a database requiring no authentication …

Expand Expanding Close

British government secretly ordered Apple to create a worldwide iCloud backdoor

British government secretly ordered Apple to create a worldwide iCloud backdoor | Photo shows partly-open door with a red room beyond it

It’s being reported that the British government secretly ordered Apple to create a security backdoor into all content uploaded by iCloud users anywhere in the world.

Apple is certain to refuse the demand, leading to the possibility of a similar privacy stand-off to the one seen between the iPhone maker and the FBI back in the San Bernardino shooter case

Expand Expanding Close

Mac malware after your passwords and credit cards will get much worse this year

So-called macOS Stealers – malware that seeks to extract personal data like passwords and credit card numbers from your machine – is expected to be significantly more prevalent this year.

A new annual report on the state of malware says that Mac owners could be at almost as much risk as Windows PC users this year …

Expand Expanding Close

Grubhub security breach exposed customer and driver data, says company

Grubhub security breach exposed customer and driver data | A food delivery rider on a scooter

A Grubhub security breach has exposed personal data for both customers and drivers, says the company, after an “incident” involving a third-party contractor.

The company has not revealed the exact scale of the security fail, but has admitted that the personal data includes names, email addresses, phone numbers, and partial credit card numbers …

Expand Expanding Close

Meta says its future AI models could have ‘catastrophic outcomes’

Meta plans to block 'catastrophic' AI models – but admits it may not be able to | Render of robot in wasteland

A Meta policy document describes the company’s fears that it could accidentally develop an AI model which would lead to “catastrophic outcomes.” It describes its plans to prevent the release of such models, but admits that it may not be able to do so.

Among the capabilities the company most fears are an AI system that could break through the security of even the best-protected corporate or government computer network without human assistance …

Expand Expanding Close

DeepSeek privacy under investigation in US and Europe; removed from App Store in Italy

DeepSeek privacy under investigation in US and Europe | App seen on an iPhone

DeepSeek privacy concerns have led to investigations being opened in both the US and Europe, and seen the app removed from the App Store in Italy. It seems likely the same will happen in other countries.

Italian’s privacy regulator questioned whether the app complied with GDPR, a tough privacy law that applies across 30 different countries …

Expand Expanding Close

SLAP and FLOP security flaws affect all current Apple devices, and many older ones

SLAP and FLOP security flaws affect all current Apple devices | M-series chip shown

Security researchers have discovered two flaws present in all current iPhones, iPads, and Macs – as well as many earlier ones. The vulnerabilities, known as SLAP and FLOP, could potentially allow an attacker to see the current contents of your open web tabs.

The flaws were introduced in the A15 and M2 chips, and are also found in subsequent ones, up to and including the latest version of each device …

Expand Expanding Close

Judge limits FBI powers to trawl data from Apple and others; Cloudflare privacy flaw

Judge limits FBI powers to use data from Apple and others | FBI command post shown

A judge has limited FBI powers to trawl through data obtained from tech giants like Apple, Google, and ISPs under FISA (the Foreign Intelligence Surveillance Act).

Separately, a Cloudflare privacy flaw has been identified in one of Apple’s IT service providers, which could have exposed the rough location of millions of web and app users before it was fixed …

Expand Expanding Close