iOS 13 could be hacked by external keyboards

iOS 13
(Image credit: Future)

Users looking to use a third-party keyboard app on their recently updated iPhone or iPad? may want to think twice after Apple issued a security warning concerning the new software.

The iPhone maker released the latest version of its mobile operating system, iOS 13, last week and the company followed this up with the recent release of iOS 13.1 and iPadOS 13.1. However, Apple has warned users of an issue affecting third-party keyboard apps in a brief advisory, which reads:

“Third-party keyboard extensions in iOS can be designed to run entirely standalone, without access to external services, or they can request “full access” to provide additional features through network access. Apple has discovered a bug in iOS 13 and iPadOS that can result in keyboard extensions being granted full access even if you haven't approved this access.”

Third-party keyboards

In the latest version of iOS, third-party keyboards can run in a standalone mode or with full access, giving them the ability to interact with other apps or access the internet for additional features such as spell check. 

However, using a third-party keyboard in full access mode also allows the developer of the app to capture keystroke data whenever you type and this includes what you write in emails, messages and even when you enter a password.

The bug Apple discovered could allow third-party keyboard apps to gain full access permissions regardless of whether or not a user approved.

The company has not released further details on the issue though it does say that the bug will be patched in an upcoming software update.

Via TechCrunch

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Pro
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Latest in News
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening