QR code images in macOS are silently executed in the background hours/days later
twitter.com
twitter.com
"Well, I was wrong. I now believe the canary token was triggered not by macOS decoding the QR, but by Firefox’s “recent” shortcuts on the home screen. I gave too much trust to a Stack Exchange answer. I have deleted the incorrect information. I regret the error."
False alarm, Get back to work folks! ;)
My comment from there:
I'll be interested to see if anyone else can reproduce this. I created a request bin [0], then created a QR code pointing at it, then downloaded that QR code. I'm not sure how often this "image scanning" is supposed to occur but just downloading it didn't cause a hit nor did the 10min I waited, nor did using QuickLook, nor opening it Preview, nor scanning it with my iPhone, the only thing that caused a request was clicking on the detected link in my iPhone camera app. Obviously if this is a background daemon that runs periodically then my test wouldn't catch it (unless I got "lucky") and for a longer-term test I'd probably want to use something other than request bin. That said request bin says it keeps bins for 48 hours so that might be enough time.
Relatedly, searching for the url in my photos library does not return the picture as a result, indicating that the scanning is not being used for indexing currently. I was trying to test with other QR codes that I happened to have in my photos library, but every one of them has the website name in the picture.
I will keep the files on my computer and continue monitoring but I am becoming very skeptical of the Twitter thread author’s methodology.
Then I do a screen capture of the QR code, and save it. At that moment I see an http query to the ip.
uname -a: Darwin Kernel Version 21.6.0: Mon Aug 22 20:17:10 PDT 2022; root:xnu-8020.140.49~2/RELEASE_X86_64 x86_64
Really shitty idea from apple...
EDIT!!!
Sorry, I think I know where the problem was: I was testing with a site I visited in safari already. It happens that after you type a couple of characters in safari address bar, and you have a cache hit in your history, safari already loads the site. While doing the experiment I visited sites which triggered hits in the history with my test site... so no. I could not really reproduce it. Maybe original tweet comes from similar error.
* https://www.the-qrcode-generator.com/ - for the QR Code
* http://10.0.1.202 and http://8.8.8.8 - for the urls
* Command + Shift + 4 - To select the area of the screen with the QR code (using the native screenshot tool, I disabled CleanShotX)
1. When Apple first switched from kexts to the network framework for apps like LittleSnitch, they exempted a ton of their own system processes (things like the App Store, and iCloud) from flowing through that framework. This change was reverted shortly after (I believe even before the GA release of that version, but don't quote me on that)
2. LittleSnitch ships with a bunch of default Allow rules designed to let expected first-party things like the App Store and iCloud work. I assume this is done so that the user experience for new LS users isn't "install app, entire system comes grinding to a halt". But these rules can be disabled by the user.
The person they are replying to said it happened instantly in their test.
I'm wondering if there is some setting in Spotlight or Finder that is required to see this behavior.
I don’t see what the fuss is about, unless there is some innuendo that data is being sent to Apple.
I don't know if this would be possible given the limited information currently available, but an example may be:
User attempts to browse anonymously through the use of A VPN, obscuring their residential IP. Website, or third party analytics on a website generate unique links and embed them in QR codes hidden on the page. A twist on tracking pixels. Browser requests, and caches image containing QR code on disk. Later, after user has disconnected from VPN their OS indexes images on the filesystem (for search purposes, or whatever, parses the QR code and requests the url contained. Malicious site/analytics firm now has additional data point (residential IP, not obscured by VPN) to correlate against.
There's also the remote potential that the QR code parsing/request functionality could have vulnerabilities. The behavior known doesn't indicate that, but it might result in exploitation with less human interaction if they are found.
URL prefetching is usually only expected to happen "on demand" while you're using stuff (e.g. generating link previews when they appear). What's described here seems to imply it is preemptively happening to files "at rest".
Also, automatic prefetching can be turned off in most places that have it, so ideally the user should be able to configure a setting to disable loading those URLs.
I don't think this is my expectation. When I receive messages overnight, I want URLs in those messages prefetched, for example. The whole point is that when I open my mail or messages the previews are already available, instead of waiting.
However in the case of the QR code, just because you "have" the QR code on your disk, doesn't imply you have an intent to visit a link it. That would be like if you had a .txt file with a string that looked like a URL inside and somehow the system while indexing the body also somehow visits the supposed URL despite it not even being a real link.
Like imagine you download a restaurant menu to check out the food and they provided it as an image (pretty standard). As a part of that image is a QR code to their Facebook page (also usually benign). In this case, let's say you are uninterested in sharing your (or specifically your IP's) interest in that restaurant with Facebook, this feature as described would share the info for you without consent.
This isn't any different from someone sending me a link to the menu at their website and them seeing my IP hit the preview there, so I'm not sure why I would care either way; if anything, downloading the menu is more intent on my part than being sent it by someone (who I may or may not even know).
The privacy implication is very different. If you enable link previews in a messaging app, you consented to any potential site getting your IP. If the restaurant adds a tracker on their page, they've consented to the 3rd party tracking from their end. But with the QR auto-loaded by the OS, neither you nor the first part have explicitly consented to the additional information being shared. There is strictly more information being shared.
> This isn't any different from someone sending me a link to the menu at their website and them seeing my IP hit the preview there
Again this is an inaccurate comparison. The closer analogy would be someone sending a link to a website and somehow your IP is exposed not only to the website that was shared, but also to every other website that the shared website links to.
Nobody has come close to showing anything malicious or that data is being exfiltrated, so why is this a problem?
Multiple bits of information are exfiltrated actually, and to a 3rd party (if it turns out the behavior is as described). The obvious one is your IP, which allows for some coarse geolocation. Also implicitly they would know you're running macOS.
The main thing this breaks down is that it assumes that if you have a QR code with a URL saved, then you must trust the target enough to let them see your IP. However, clearly not everyone agrees.
Pair this with a zero-day in the HTTP request library and an image becomes the initiation of an attack that leads to a vulnerable client connecting to a malicious endpoint.
Could also easily be used to track users in new ways.
Just two scenarios that immediately comes to mind.
QR codes often include marketing trackers, for one really common examples.
1. Copy/paste the link and send it to himself over iMessage from his laptop, perhaps to test it out on his phone or vice versa?
2. Send the QR code itself from his phone to his laptop or vice versa perhaps to test out scanning?
The fact that the user agent matches that of iMessage screams that the code is somehow in a iMessage thread and iMessage is trying to refresh a preview thumbnail, detect an app clip, or make sure a url is accessible. Add to that the fact that this requests came in the morning suggesting they happened when he turned his laptop on or unlocked his phone to check messages, etc.
The user agent is the one used by the Link Presentation framework. It shouldn't be too much to dig through the shared cache for binaries that link to this framework and see if there are any QuickLook ones.
Moreover joshstrange in this thread and others I know from elsewhere aren't able to reproduce. Yet the original unsubstantiated tweet has 500 retweets and will probably reach thousands as the west coast logs in this morning.
Say you own a bar, nightclub, popular tourist location, or whatever. Place specific QR codes at locations of encoding URLs pointing to a server you own, and you will be able to count how many times an iPhone user took a photo that included said QR code (or, if background scanning is active even before the picture is taken, how many times an iPhone was pointed towards it).
Not that this would likely provide any valuable information for a malicious actor, nor could it really be done covertly. It's more of a thought experiment.
Just tested this and no matter how many times I point Camera at my QR code, it doesn't access the URL until I specifically click on the little yellow callout box.
I’d suspect it’s indexing for search rather than a security protocol - i feel like anybody security minded would have approached this differently
Even the title uses the word "executed" as if a QR code is "runnable" in some way; it's not. QR code related hacks are not some magical "scan this image and get pwnd", they're related to browser exploits and other methods of forcing code execution by way of the browser.
To my knowledge there have never been any "offline" QR code hacks, where simply scanning the QR code itself has ever lead to an exploit. AV is generally dumb, but simply converting a QR code itself is harmless.
That said, I agree - parsing the QR code itself isn't really a vector I'd worry much about.
https://www.theregister.com/2016/05/17/tavis_ormandy_zeroes_...
https://www.computerworld.com/article/2493275/researcher-fin...
So it’s exploding the QR to see where the link goes?
Well, it's certainly fantastic for fingerprinting. You could put some UUID in the QR code and have macOS tell you who the IP address is every few days.
@Dang, should these threads be merged?
For the record I tried to reproduce this and so far the URL has not been visited.
It's not supposed to be happening promptly; reproducing (or not) will take a couple days AFAIK?
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWebKit/601.2.4 (KHTML, like Gecko) Version/9.0.1 Safari/601.2.4 facebookexternalhit/1.1 Facebot Twitterbot/1.0"