A security researcher has discovered that the iPhone 11 Pro intermittently collects location data even when location services are disabled on the device. Apple has confirmed to the researcher that this is expected behavior which is a bit puzzling.
“We do not see any actual security implications,” an Apple engineer wrote in a response to KrebsOnSecurity. “It is expected behavior that the Location Services icon appears in the status bar when Location Services is enabled. The icon appears for system services that do not have a switch in Settings.”
Apple’s response basically means that there are certain system services or parts that will access a user’s location from time to time even if location services are disabled. All location data sent to Apple is anonymized so it does not pose a privacy risk but the company not being clear about it is going to anger a lot of privacy-conscious folks out there.
While not mentioned, the same behavior is likely going to be exhibited by other iPhones as well including the iPhone 11.
It is possible that Apple is collecting location data even when the option is disabled for Find My device feature. The new Find My app in iOS 13 works even in offline mode using a number of advanced techniques. Apple is yet to reply to more follow up questions from the security researcher which should provide further clarity on this situation.[Via Krebs on Security]