Apple will finally address a Safari restriction workaround that has been around for years after the bug was highlighted by The Wall Street Journal's Joanna Stern. Kids who are restricted from viewing certain websites with the Screen Time feature are able to paste a string of characters in the address bar in Safari in order to get around parental controls.
In a report on Screen Time, Stern says that she was able to use a string of characters on her son's iPad, bypassing the restrictions that prevent access to websites with pornography, violent images, and more. She was able to get around Screen Time on devices running iOS and iPadOS 15, 16, and 17, as well as macOS Sonoma.
In a statement to Stern, Apple said that it is aware of an "issue with an underlying web technology protocol for developers, which allows a user to bypass web content restrictions." A fix is planned for "the next software update."
Security researchers that spoke to Stern said the bug was first reported to Apple in March of 2021, after it was found that inputting a string of characters would get around website restrictions implemented by parents and web blacklists on company devices. The hack worked to bypass restrictions on iPhones, iPads, and Macs.
Apple told the researchers that it was not a security issue, and instead directed them to submit a report using the Feedback tool. After the report was submitted, there was no word back from Apple. Attempting to resubmit the bug to Apple was met with no response.
Apple ignored the issue for three years until Stern was contacted and publicized the problem. It appears that the workaround was not well-known or widely exploited, as the two security researchers that discovered it never shared it.
In addition to promising a fix, Apple said that it is committed to improving the process that's used to receive and escalate bug reports.
Stern's report highlights several other bugs with Screen Time, including issues with app limits, Screen Time usage charts, notifications for more time, and Ask to Buy. Apple improved Screen Time with iOS 17.5, implementing fixes for app and device usage tracking, app limits, and time requests, but the company says there will be additional updates in upcoming software releases.