Mysk: iPhone apps including Facebook, Instagram, Threads, TikTok, and X are skirting Apple's privacy rules to collect user data through push notifications
Security researchers say apps including Facebook, LinkedIn, TikTok, Twitter, and countless other use notifications as a loophole to skirt privacy protections.
Context & Ripple Effects
This report extends a long-running pattern in mobile privacy research: popular apps have repeatedly been found transmitting personal information to third parties, while an earlier study found some iOS apps still sent identifiers after users opted out under ATT. Post-ATT identifier sharing is the closest precedent because it exposed a gap between a platform privacy control and application behavior.
The concern also fits prior findings that apps could capture more than users reasonably expect, from session-recording analytics SDKs to persistent clipboard access. The new allegation matters because it identifies notifications—an ordinary system feature—as a possible route around privacy safeguards.
First-order effects
- Apple faces pressure to determine whether push-notification data practices violate its privacy rules and, if so, to enforce or clarify those rules for the affected apps.
- Facebook, Instagram, Threads, TikTok, X, LinkedIn, and other developers using comparable notification flows face heightened scrutiny over what data is collected and how it is disclosed to users.
Second-order effects
- Developers that rely on notification-linked data will need to audit those flows; any enforcement could remove a measurement or targeting input without changing the user-facing notification feature.
- The finding gives privacy researchers and regulators a concrete surface to test, shifting attention from consent prompts alone to whether platform controls can be bypassed through adjacent APIs.
Third-order effects
- If such workarounds recur, mobile privacy will be judged increasingly by enforceable technical boundaries rather than by high-level opt-out settings or policy language.
- Platform owners may need to apply privacy restrictions across connected system services, or risk a cycle in which each tightened control pushes data collection to another permitted channel.
The trend: This is one data point in the broader shift from privacy promises centered on user consent toward scrutiny of the technical pathways apps use to preserve data collection.