OS X Spotlight Glitch Exposes IP Addresses and Other System Details to Spammers

A privacy glitch in Spotlight search for OS X may leak private details, including IP addresses, to email spammers. The flaw was first reported by German tech news site Heise and replicated in tests performed by IDG News Service.

spotlight-search
The issue affects OS X mail users who have followed conventional security recommendations to turn off the "load remote content in messages" option in the Mail app. This setting prevents the loading of remote content such as images, including "tracking pixels" that are used by spammers to harvest information when people open an email.

A glitch arises when OS X Mail users utilize Spotlight search in OS X, which includes emails in the search results. Spotlight ignores the remote content block preference from Mail and loads the remote email files as part of the search process. Once Spotlight loads one of these tracking pixels, spammers can glean details such as the IP address, OS X version, browser details, and the version of Quick Look being used.

The Spotlight preview loads those files even when users have switched off the "load remote content in messages" option in the Mail app, a feature often disabled to prevent email senders from knowing if an email has arrived and if it has been opened. What's more, Spotlight also loads those files when it shows previews of unopened emails that landed directly in the junk folder.

Currently, the only way to block this information leak is to block Spotlight from including emails in search results entirely by opening System Preferences and unchecking the "Mail & Messages" option for Spotlight. Apple has yet to comment on this Spotlight privacy glitch.

Related Forum: OS X Yosemite

Popular Stories

iOS 18 WWDC 24 Feature 2

iOS 18 Beta Available Next Week With These 25 New Features Expected

Tuesday June 4, 2024 9:57 am PDT by
iOS 18 is just days away, with Apple set to unveil the software update during its WWDC keynote on June 10. Many new features and changes are expected for the iPhone, with more details outlined in our rumor recap below. The first beta of iOS 18 should be made available to members of the Apple Developer Program immediately after the WWDC keynote, and a public beta will likely follow in July....
ATT Banner

Some AT&T, T-Mobile and Verizon Customers Report Issues With Calls [Update: Fixed]

Tuesday June 4, 2024 10:51 am PDT by
There appears to be an outage with at least one U.S. cellular carrier, with customers unable to place or receive calls. AT&T, T-Mobile, and Verizon customers have been complaining about the issue on social networks, and there are also reports of outages on the Down Detector website. According to a statement from AT&T, the outage is affecting calls between carriers in the United States. All...
iPhone 16 Pro Front Update Blue

Revealed: Complete iPhone 16 Pro and iPhone 16 Pro Max Dimensions

Wednesday June 5, 2024 3:38 am PDT by
This year, Apple is set to increase the size of its premium iPhones, and it will be the first size update we've had in several years. While we've known for some time that the iPhone 16 Pro will measure in at 6.3 inches (up from 6.1) and the Pro Max will measure in at 6.9 inches (up from 6.7), we have not had a complete picture of every dimension, until now. Despite being bigger phones, one...
iOS 18 Siri Integrated Feature

iOS 18: These iPhones Won't Support New Apple Intelligence AI Features

Tuesday June 4, 2024 5:04 am PDT by
Apple is planning a major AI overhaul in iOS 18, with a feature set it is referring to as "Apple Intelligence." However, these new features will not work on older iPhones, even if they do appear on the new operating system's device compatibility list. Apple's initial AI roadmap for iOS 18 is said to come in two parts: Basic AI features that will be processed on-device, and more advanced...
Folium Alpha Sapphire Feature

Nintendo 3DS Emulator for iPhone Released in App Store With Caveats

Tuesday June 4, 2024 7:08 am PDT by
Folium has become the first Nintendo 3DS emulator for the iPhone available in the App Store, although there are some caveats to be aware of. Foremost, this is the first Nintendo emulator on the App Store that costs money. Folium developer Jarrod Norwell is charging $4.99 for the app, which is a bold choice given that Nintendo recently sued the developers of Yuzu, a Nintendo Switch emulator...
bartender app

PSA: Bartender Mac App Under New Ownership, But Lack of Transparency Raises Concerns

Tuesday June 4, 2024 3:22 pm PDT by
Popular Mac app Bartender appears to have been quietly sold approximately two months ago, with neither the prior owner nor the current owner providing customers or potential customers with information on the sale. The transaction came to light after some Reddit users saw a warning from MacUpdater letting them know that the company behind Bartender had been silently replaced. MacUpdater...

Top Rated Comments

thejadedmonkey Avatar
123 months ago
Oh for goodness sake, don't let them know my version is Yosemite and what browser I'm using! And, *gasp*, the version of QUICK LOOK?! This is an outrage.

/s
I don't think you understand what the article means.

Let me explain. If you block the tracking pixel from loading, the spammer will never realize that you received the email, and may eventually stop sending them. If they do realize that you receive the email, then they can get your IP address, know that the email address is valid, cross reference your purchasing habits with your IP address, and target you specifically with Facebook ads.

That's a major gaping privacy hole in OS X that needs to be patched.
Score: 46 Votes (Like | Disagree)
joshwenke Avatar
123 months ago
Oh for goodness sake, don't let them know my version is Yosemite and what browser I'm using! And, *gasp*, the version of QUICK LOOK?! This is an outrage.

/s
Score: 11 Votes (Like | Disagree)
DarkCole Avatar
123 months ago
Well thanks for the heads up, I've unchecked the setting in Spotlight.
Score: 8 Votes (Like | Disagree)
samcraig Avatar
123 months ago
As I've said before in other threads. Regardless of whether or not this is "harmful" to some or all - if there's a security issue and it's known, it should be fixed. End of story. No judgement. Simple as that.
Score: 7 Votes (Like | Disagree)
brentmore Avatar
123 months ago
Yet another reason why Little Snitch is my favorite tech tattletale.
Score: 7 Votes (Like | Disagree)
BlendedFrog Avatar
123 months ago
Another reason not to use the crappy mail app. Now I know why I have always stuck to using the webmail interface.

Will Apple ever get their act together and overhaul the damn app and actually make it usable?
Score: 7 Votes (Like | Disagree)