Researchers who flagged TikTok and 55 other iOS apps for clipboard snooping in March say the majority of apps they identified still continue the practice
Passwords, bitcoin addresses and anything else in clipboards are free for the taking. — In March, researchers uncovered …
Context & Ripple Effects
In March, researchers flagged TikTok and 55 other iOS apps for reading users' clipboards — a channel that exposes passwords, bitcoin addresses, and anything else copied. The story escalated when Apple's iOS 14 began surfacing a notification each time an app touched the clipboard, forcing TikTok to publicly commit to stopping and catching LinkedIn copying clipboard contents on every key press, which it blamed on a bug.
This follow-up from the same research team is the accountability check: months later, they say the majority of the apps they identified are still reading clipboards. It matters because voluntary pledges, not platform enforcement, have been the only fix so far.
First-order effects
- The named apps — TikTok foremost among them — face renewed reputational pressure just as Apple's iOS 14 clipboard notifications make every read attempt visible to users in real time.
- Users copying passwords or bitcoin addresses into these apps remain exposed today, since the majority of flagged apps have not changed behavior.
Second-order effects
- Apple is pushed toward making its iOS 14 clipboard alert stricter or opt-out rather than advisory, since app-level promises like TikTok's have demonstrably not held across the cohort.
- Other large iOS developers now audit their own SDKs proactively to avoid becoming the next LinkedIn-style disclosure once the notification system ships broadly.
Third-order effects
- If disclosure-by-OS becomes the enforcement mechanism, iOS privacy shifts from policy documents to runtime transparency — a pattern the related coverage echoes in [[a:848675|researchers finding Facebook, Instagram, Threads, TikTok, and X skirting Apple's rules via push notifications]] years later, and in Apple's earlier move to ban 256 apps over an abusive ad SDK back in 2015.
The trend: iOS privacy enforcement is migrating from app makers' voluntary assurances to OS-level runtime disclosure, with Apple's alerts exposing practices that pledges alone never stopped.