Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

charbelgt

macrumors newbie
Original poster
Nov 8, 2023
2
0
When viewing a PDF that is stored in iCloud using a web browser signed into your iCloud account, you can copy the URL of the PDF and paste it into another browser that is not signed in and still view the document. This seems like a massive security flaw - is there something I'm missing here, or is there somewhere that I can report this to Apple?

To confirm, this happens even when all iCloud sharing features are disabled. It appears that iCloud generates publicly accessible URLs for PDFs and JPEG files stored in iCloud Drive, regardless of sharing status
 

Morac

macrumors 68020
Dec 30, 2009
2,182
621
Do you have enhanced data protection enabled? If so that shouldn’t be possible.

If not it’s probably cached or something.
 

charbelgt

macrumors newbie
Original poster
Nov 8, 2023
2
0
I don't have enhanced protection enabled, but this shouldn't need it. Documents stored in iCloud that aren't explicitly shared shouldn't be served on publicly accessible URLs as it appears they are. Pretty certain it's not a caching thing, but curious if anyone else can replicate this.
 

sers

macrumors 6502
Jan 11, 2006
333
638
Just tried this and can confirm I can copy the URL of PDF stored in my iCloud Drive into another browser that's not signed into my iCloud account and it will display the document.
 

Morac

macrumors 68020
Dec 30, 2009
2,182
621
My guess is it’s likely being cached at the server side (aka CDN caching). That’s not ideal, but since the URL isn’t public and the cache will clear it’s probably not a big deal.

If you want security you should enable enhanced security.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.