Malvertising: Unscrupulous website ads again auto-redirecting users to App Store from Safari

“Website advertisement companies have found a way to circumvent the protections introduced in iOS 8 to stop users from being kicked to the App Store because of certain cleverly-coded JavaScript advertisements,” Benjamin Mayo reports for 9to5Mac.

“I am now experiencing this myself, and it makes browsing on the iPhone unusable. Browsing to websites such as Reddit and Reuters and others now automatically open the App Store… It’s unclear why this has started happening to me (it wasn’t happening yesterday and not everyone experiences it), but Twitter searches show that is also affecting others. It’s basically impossible for me to browse the web on my phone due to this. Using alternate browsers has no effect. Disabling JavaScript stops this from happening, but that isn’t really feasible as many websites rely on JavaScript to function, so it doesn’t really count as a reasonable solution,” Mayo reports. “This flared up as a serious issue last year, when users found they were being taken to random App Store pages without granting any kind of permission.”

“In iOS 8 beta 2, Apple supposedly had remedied the issue: ‘Safari now blocks ads from automatically redirecting to the App Store without user interaction.’ However, it seems that ad companies have now managed to work around these safeguard,” Mayo reports. “This is Apple’s problem to fix, not an attack on the websites… All of these websites use third-party networks that are outside of their control — it’s not their decision to cause the redirections. We’ve reached out to Apple for comment on the issue.”

Read more in the full article here.

MacDailyNews Take: Okay, so we’ve obviously been through this before, so we’ll refer you to this post for more info if you haven’t seen it, yet:

Shady app install ads automatically redirecting mobile users to App Store, Google Play – January 16, 2015

For some time now, we’ve been doing what we can, at a cost to the site, by turning off entire ad networks and having affected users report back if the rogue redirects have stopped or not (it’s not happening to everybody; in fact, we can’t replicate the problem on any of our iOS devices. We’re going to try Reddit and Reuters to see if we can trigger them there via Safari for iOS). We also can see what’s happening in our Inbox. When the flow of complaints that accuse us of being “stupid fscking greedy bastards” cease (those are the “nice” ones), then we know we’ve hit upon an issue.

Currently, as of Monday evening, we think we’ve got these ad networks isolated (off) and the redirects have stopped (or slowed) according to our helpful readers (like Dominick P., for one prominent example – thanks, Dominick for all your help on this!) and because the email missives have ceased.

Again, as Mayo reports, we’re not causing these redirects. Reddit is not causing the redirects. Neither is Reuters. Beyond Apple’s responsibility for their users’ experience, the third-party ad networks really need to get a handle on this and vet who they allow into their systems. Right now, some of these networks are infiltrated by criminals who are spreading malvertising. If they fail to clean up their acts, these ad networks will lose publishers, and eventually their businesses.

If you experience an auto redirect while browsing MacDailyNews.com via Safari on your iPhone, iPad, or iPod touch, please drop us a friendly email, so we know that they’re back and we can try to block them.

You can stop this from happening in your browser of choice on your iOS device by enabling Guided Access in Settings>General>Accessibility. This will prevent the App Store from being launched out of Safari unless you want it to do so.

In closing, this continues to be an absolutely lovely experience all around and we hope it ends sooner than later. Please, Apple, save us if you can!

Related article:
Shady app install ads automatically redirecting mobile users to App Store, Google Play – January 16, 2015

55 Comments

  1. Well, I don’t use the app, I use MDN in the browser on my iPhone, so I haven’t had this problem. However, I have had page errors loading, pages becoming entirely unresponsive, and the links on the right-hand side of the page always fail with a “cannot connect to localhost” error… very strange.
    Today however, I experienced something I have never experienced on the MDN or any other website. When I logged in, a pop-up message warned that my Flash was out of date, which it wasn’t. I dismissed the message, and immediately a download was triggered – MPlayer.dmg. Upon inspection of this download, I can see it is NOT MPlayer, but something else which I am not stupid enough to investigate further. ClamXAV did not find a problem with the downed.
    Unfortunately, I reloaded the page, without error, but lost the ability to inspect the source code to see what happened.
    Has anyone else seen this today??? MDN, comments?

    dmx

    1. As of now when I try and tap a link posted on Twitter the page doesn’t go on to anywhere it just locks up. I tell it to open up in safari and it tries to but remains locked but I can read just before the http name of the actual site it’s trying to go to is this. dekuri.co/php I don’t have a clue. And BTW Twitter Support are useless.

      1. Sounds like those are some clues as to how this is being done. I had something like this happen a few years ago when I installed a Firefox extension, but as it’s apparently happening in different browsers I don’t think that’s the case here.

        When that happened to me it was quickly obvious what the culprit was, and I simply uninstalled it. I rarely used FF anyway, but had to do some specific testing.

  2. I have been plagued by this same browser hijack. MDN is the only site that I have seen it on. I was hopeful when MDN said that the behavior could be eliminated by turning on ‘Guided Access’ on the iPhone.

    Unfortunately, that didn’t work for me. Now I get Ads that take over the entire screen. And when you press the ‘X’ to dismiss the Ad, you find that it has destroyed most of the MDN page, and only leaves a single Ad visible on the page.

    MDN has become totally inaccessible to me from the iPhone.

    I’m considering switching to an RSS reader to get my Mac news. Any suggestions?

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.