iPhone 11 Pro discovered to still seek user location data despite settings

The discovery suggests a privacy vulnerability exists in the new flagship handset or the latest iOS, or both, KrebsOnSecurity reports.

Steven Musil Night Editor / News
Steven Musil is the night news editor at CNET News. He's been hooked on tech since learning BASIC in the late '70s. When not cleaning up after his daughter and son, Steven can be found pedaling around the San Francisco Bay Area. Before joining CNET in 2000, Steven spent 10 years at various Bay Area newspapers.
Expertise I have more than 30 years' experience in journalism in the heart of the Silicon Valley.
Steven Musil
2 min read

The iPhone 11 Pro may still be trying to get users' location data even after they've disabled the privilege.

Angela Lang/CNET

The iPhone 11 Pro apparently has a habit of behaving in a way its users have expressly forbidden. Apple's flagship handset intermittently tries to collect people's location information, despite settings on applications and system services that indicate the data shouldn't be requested, according to a report published Tuesday by KrebsOnSecurity.

Apple's privacy policy for the iPhone's Locations Services says the handset "will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers (where supported by a device) in an anonymous and encrypted form to Apple, to be used for augmenting this crowd-sourced database of Wi-Fi hotspot and cell tower locations."

The policy explains how to disable location-based services, but security reporter Brian Krebs found that some system services for the iPhone 11 Pro -- and possibly other iPhone 11 models – can't be disabled by users without turning off locations services. Krebs said his discovery suggests that a privacy vulnerability exists in either the new iPhone Pro or iOS 13 or both.

Apple has taken high-profile actions championing privacy. In 2016, for instance, it refused to alter its software so that the FBI could access an iPhone 5C tied to the San Bernardino terrorist incident, arguing that the change would create a back door to all other iPhones. Last year, it unveiled features for its Safari browser that could disable tracking tools Facebook and Twitter use to keep tabs on people's browsing habits.

Krebs said he sent a video to Apple in November that showed the phone still seeking location information when apps and system services were set to "never" request location information but main Location Data service was still active.

Apple's privacy policy explains that a small diagonal upward arrow appears to the left of the battery icon when you disable location services, but Krebs's video shows that the handset still periodically requests the data, even while the system services are disabled and the arrow icon still appears.

 "We do not see any actual security implications," an Apple engineer wrote in a response to KrebsOnSecurity. "It is expected behavior that the Location Services icon appears in the status bar when Location Services is enabled. The icon appears for system services that do not have a switch in Settings."

Apple didn't immediately respond to a request for comment.

Compare photos from the iPhone 11 Pro against last year's iPhone XS

See all photos