“This app forced me to give it a good rating before I could use it.”
twitter.com
twitter.com
This is not just possible, it's actually extremely easy to do.
Hoping to share a proof of concept soon.
It’s not more unacceptable for an exploit to exist than it is for the exploit to be used. One is a risk, the other is actively attempting to do harm.
This should be the case for all such interactions, including permissions, image library selection etc.
I realize APIs are hard to change but this is one of the cases where I think Apple should just fix it even if it bricks well-behaved apps until they can be patched (which could be never).
They are blocking the buttons. https://twitter.com/_inside/status/1397540108971266049