ios-uiactivity-sharing.md (3634B)
1 --- 2 title: "iOS UIActivity Sharing" 3 section: "Mobile" 4 sectionSlug: "mobile-pentesting" 5 sourcePath: "src/mobile-pentesting/ios-pentesting/ios-uiactivity-sharing.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/ios-pentesting/ios-uiactivity-sharing.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # iOS UIActivity Sharing 14 15 ## UIActivity Sharing Simplified 16 17 Since iOS 6, applications can present a system activity view to share text, URLs, images, and other items with services such as AirDrop or compatible app extensions.<sup>[[2]](#references)</sup> 18 19 Apple's `UIActivity.ActivityType` documentation enumerates built-in activity identifiers. Developers can set `excludedActivityTypes`, but the security review must also inspect the actual items and any custom activities.<sup>[[3]](#references)</sup> 20 21 ## **How to Share Data** 22 23 Attention should be directed towards:<sup>[[1]](#references)</sup> 24 25 - The nature of the data being shared. 26 - The inclusion of custom activities. 27 - The exclusion of certain activity types. 28 29 Sharing is facilitated through the instantiation of a `UIActivityViewController`, to which the items intended for sharing are passed. This is achieved by calling: 30 31 ```bash 32 $ rabin2 -zq Telegram\ X.app/Telegram\ X | grep -i activityItems 33 0x1000df034 45 44 initWithActivityItems:applicationActivities: 34 ``` 35 36 Review the items and custom activities passed to `UIActivityViewController`, along with any configured `excludedActivityTypes`. 37 38 ## **How to Receive Data** 39 40 The following aspects are crucial when receiving data:<sup>[[1]](#references)</sup> 41 42 - The declaration of **custom document types**. 43 - The specification of **document types the app can open**. 44 - The verification of the **integrity of the received data**. 45 46 Without source, inspect `Info.plist` for `UTExportedTypeDeclarations`, `UTImportedTypeDeclarations`, and `CFBundleDocumentTypes`. These legacy UTI keys still appear in deployed apps; newer source commonly uses the Uniform Type Identifiers framework and `UTType` APIs.<sup>[[4]](#references)</sup> 47 48 Exported declarations define types owned by the app, imported declarations describe types owned elsewhere, and document types associate those identifiers with the app's open/import behavior.<sup>[[4]](#references)</sup> 49 50 ## Dynamic Testing Approach 51 52 To test **sending activities**, one could:<sup>[[1]](#references)</sup> 53 54 - Hook into the `init(activityItems:applicationActivities:)` method to capture the items and activities being shared. 55 - Identify excluded activities by intercepting the `excludedActivityTypes` property. 56 57 For **receiving items**, it involves:<sup>[[1]](#references)</sup> 58 59 - Sharing a file with the app from another source (e.g., AirDrop, email) that prompts the "Open with..." dialogue. 60 - Hooking `application:openURL:options:` among other methods identified during static analysis to observe the app's response. 61 - Employing malformed files or fuzzing techniques to evaluate the app's robustness. 62 63 ## References 64 65 - [1] [OWASP MASTG — Testing App Extensions](https://mas.owasp.org/MASTG/tests/ios/MASVS-PLATFORM/MASTG-TEST-0072/) 66 - [2] [Apple — `UIActivityViewController`](https://developer.apple.com/documentation/uikit/uiactivityviewcontroller) 67 - [3] [Apple — `UIActivity.ActivityType`](https://developer.apple.com/documentation/uikit/uiactivity/activitytype) 68 - [4] [Apple — Defining file and data types for your app](https://developer.apple.com/documentation/uniformtypeidentifiers/defining-file-and-data-types-for-your-app)