Critical iOS Vulnerability Exposes User Data to Tracking via 84 Hidden Streams
Key Takeaways Forensic researchers have uncovered 84 previously undocumented data streams within Apple’s Biome framework across iOS 18 and iOS 26. These streams passively record extensive user...
Key Takeaways
- Forensic researchers have uncovered 84 previously undocumented data streams within Apple’s Biome framework across iOS 18 and iOS 26.
- These streams passively record extensive user activity, including app usage, location data, messages, and device interactions.
- While not a vulnerability in itself, this data can be leveraged for detailed user tracking and forensic analysis.
- Some data streams retain information for months, significantly longer than the commonly assumed 28-day retention period for iOS activity.
- Existing forensic tools currently extract only a fraction of this available data, underscoring the need for updated analysis methods.
A recent deep dive into Apple’s proprietary Biome framework has revealed a staggering 84 hidden data streams that meticulously log user activity on iPhones. This discovery, while not pointing to a malicious exploit or active intrusion, highlights how deeply integrated iOS services can accumulate a comprehensive record of an individual’s digital life.
The findings illuminate a significant shift in the landscape of iOS forensics. Data that was traditionally centralized in the KnowledgeC database is increasingly migrating into Biome. This framework is foundational to features like predictive text, personalized recommendations, Siri’s intelligence, and other tailored user experiences. The extensive data trail generated by Biome also provides critical context to previously reported privacy concerns, such as the retention of deleted notifications.
Digital forensics experts at Zena Forensics said in a report that their discovery came during an in-depth examination of full filesystem acquisitions from multiple iPhones running iOS 18 and iOS 26. Their investigation underscores that many current forensic tools only scratch the surface, reading a fraction of the available data within the Biome framework.
The ramifications of these findings are significant for digital investigators, privacy advocates, and everyday iPhone users. While designed to enhance the user experience, this extensive data collection can inadvertently facilitate the reconstruction of highly detailed user activity timelines, especially when cross-referenced with application logs, network traffic, and other device artifacts.
Hidden Biome Data Streams
Biome’s presence in iOS dates back to iOS 14, according to the analysis, with its data collection capabilities expanding considerably through iOS 15 and iOS 16. With iOS 17, Apple introduced the newer SEGBv2 storage format, further solidifying Biome’s role as a central repository for contextual and behavioral information.
The researchers pinpointed 16 valuable data streams within Biome’s system-level repository and an additional 68 in the user-level repository. Collectively, these 84 streams contain a wealth of information. This includes, but is not limited to, evidence related to application usage and installations, Safari browsing history, physical location visits, Wallet transactions, CarPlay activity, Screen Time metrics, wireless network connections, power events, Siri interactions, keyboard input, media playback, and even activity associated with Apple Intelligence features.
It’s important to note that the depth and breadth of data within each stream can vary. Factors such as the specific iOS version, individual device activity patterns, user settings, and the type of forensic acquisition performed all influence the available information. Nevertheless, the sheer scale of the Biome framework provides investigators with numerous new avenues for inquiry beyond traditional data records, much like advanced <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8603c07a-371b-4120-b1a1-5b8e70965d16/Researchers-Find-84-Hidden-iOS-Data-Streams-Tracking-Apps-Locations-and-Messages.pdf?AWSAccessKeyId=ASIA2F3EMEYE4XBLFIS3&Signature=FSL9bD%2F0r%2FikuNB0IGPfkMjS%2BdQ%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEIT%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIC9IVue58W%2Ff0kZotNuQz8gClQB4UpNukm8ylQUdEiAuAiAPWNgffGkwwo0zDWTIggrWpGnIdvy10XZFL8PALhwvPyrzBAhNEAEaDDY5OTc1MzMwOTcwNSIMSIxk4JcbXOhDyDYQKtAEiiKfNKjUtbNiBouTx95Ta0bUKNEtbJAy2RpDHNRgAkjBv1JswNVNASEGrg1YVSCrMb8%2BntEsemZE1rvnzFk9iKXxA1XmToMGCVROOcFhbjGS66%2FB0v3LPAwaAAVXYQYat%2BD8zl%2BeH%2B9gdpsS6fst2Jq5uZJKx%2F%2FouGAvVdL5wceqhzpwX6lq%2Bct7YpsgmCOEcFYhILb7n%2B%2FCNOou9VZpgNqo%2BUyo2zVYPK%2FZDqoThXwLdwtI2tRIeJsOlxWhpdkd%2Fck5peelwi%2FdspIWoRBp2G1VdfjARokHwbezN8Tr6r9siys%2FJvnaRrvB6iA0a5CVQPax1AUmfB6JwCkITqrSn1dw5e3OGKsSKe5FfbTzWjgTQbre3bhK5%2FKr1V%2F9xx6fPrZ8xAMxKDS3fQhJm%2Bp09x6Z6Go5bOFmgDWlg7qSnu1cuYS%2FdHKjTl9e7%2Fe8dOWx3s7KIaGPvy5PAjJ97wmO4RXIRTJhpIFAQK8BLFFFkraeBGRkq1laGlFZ21ujLhTRwu3yDZZ1kll6KHkFU7SOFwp3WcxRjDNh7OtGzPI9G0U99X8YseeB4vK7WrNQvMTWolwwk6DSFLpSuGToHnyNcgUE21cYh5YJNED%2B7EWnGD9NFqwJX151e7Smam0rRIo9zyjcYWHGn2E10v%2FbTNW55eoVahPFHQRGhCzcGZp
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.