There’s a bug in the UWP API that lets appropriately programmed apps look at all of your data. Gรผnter Born says: (The malicious UWP) app is not limite
[See the full post at: Newly discovered data access breach in Win10 UWP (Metro, “Store”) apps]
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Newly discovered data access breach in Win10 UWP (Metro, “Store”) apps
Home » Forums » Newsletter and Homepage topics » Newly discovered data access breach in Win10 UWP (Metro, “Store”) apps
- This topic has 17 replies, 11 voices, and was last updated 6 years, 5 months ago.
Tags: broadFileSystemAccess
AuthorTopicViewing 5 reply threadsAuthorReplies-
WildBill
AskWoody PlusOctober 27, 2018 at 3:03 pm #227597Well, that tears it. Even if Microsoft fixes the bug, I’ll never move to Win10 whatever. Neither Home nor Pro! Yes, I know it will be fixed… but what’s to stop some coder from breaking it again? It’s always been a matter of trust, but MS just lost mine for good when it comes to Windows 10. As long as they don’t break Win8.1 before 2023… bugs start popping up after January 2020, then Linux Mint, here I come!
Bought a refurbished Windows 10 64-bit, currently updated to 22H2. Have broke the AC adapter cord going to the 8.1 machine, but before that, coaxed it into charging. Need to buy new adapter if wish to continue using it.
Wild Bill Rides Again...4 users thanked author for this post.
-
Susan Bradley
ManagerOctober 27, 2018 at 9:45 pm #227629The store process means that apps are vetted so isn’t this a theoretical attack rather than one we will see in reality?ย It’s like the iPhone bugs that they say “first you have to jailbreak the device”…. well yeah….
Susan Bradley Patch Lady/Prudent patcher
1 user thanked author for this post.
-
anonymous
Guest -
Susan Bradley
ManagerOctober 28, 2018 at 1:55 am #227642
-
-
-
Jan K.
AskWoody Lounger -
lurks about
AskWoody LoungerOctober 28, 2018 at 9:25 am #227670What I understood was the problem is UWP apps were granted extensive file reading (writing?) privileges even when the developer did not invoke them or request them. Thus it sounds like a carefully crafted app could harvest files from anywhere on the box and send them to their mothership. How practical this mode would be; I do not know.
1 user thanked author for this post.
-
anonymous
GuestSeff
AskWoody PlusOctober 27, 2018 at 3:21 pm #227601Surely not! Windows 10 is the most secure version of Windows, is it not?
Thanks for the info, Woody.
2 users thanked author for this post.
-
Charlie
AskWoody Plus
lanceboil
AskWoody Loungerb
AskWoody_MVPOctober 27, 2018 at 6:18 pm #227618Thereโs a bug in the UWP API that lets appropriately programmed apps look at all of your data.
But there are unlikely to be any such apps (apart from Microsoft’s App Installer and Diagnostics Data Viewer) because;
If you submit an app to the Store that declares this capability, you will need to supply additional descriptions of why your app needs this capability, and how it intends to use it.
Docs / Windows / UWP / Develop / Files, folders, and libraries / File access permissionsAnd the capability can be disabled per device, per user or per app.
As for the app crash on 1809; that sounds like a programmer error:
Some capabilities provide apps with access to a sensitive resource. These resources are considered sensitive because they can access the user’s personal data or cost the user money. Privacy settings, managed by the Settings app, let the user dynamically control access to sensitive resources. Thus, it’s important that your app doesn’t assume a sensitive resource is always available.
Docs / Windows / UWP / Develop / Packaging apps / App capability declarations1 user thanked author for this post.
-
woody
Manager
mn–
AskWoody LoungerOctober 29, 2018 at 3:14 am #227837… so, let’s see…
1. UWP apps from outside the Store have direct filesystem access on by default in previous versions of Windows 10, but off by default in 1809. The bug is that the permission dialog doesn’t display automatically on first instance of the specific app requiring this permission.
2. UWP apps that need direct filesystem access and don’t have it, throw an exception that defaults to crashing the app unless caught. The permission state can change while app is running and takes effect immediately.
Now, unless there’s something even weirder going on, surely the user’s UWP apps still run in the normal user context and thus only have at most as much capability as the user’s non-UWP processes, thus not causing any inherent extra risk just due to being UWP? Such as in this case with a business-specific internal app, apparently…?
What I find potentially somewhat risky is the unexpected state change, which logically might prevent the app from saving its data to disk, thus having the potential for data loss. This is not markedly different from non-UWP apps running into an unexpected permissions problem at file open time but might differ for files that were already open, or does the UWP platform prevent continuously open files or something?
Not going into whatever may be going on with the Store – the “vetting” processes would reduce risks but not eliminate.
-
mn–
AskWoody LoungerOctober 29, 2018 at 8:23 am #227856… hm, it seems that the “broad filesystem access” privacy settings entry just isn’t there at all in at least W10 1709…
Now, fromย https://stackoverflow.com/questions/49728846/uwp-c-sharp-folderpicker-without-dialog and elsewhere, broad filesystem access was supposed to either not exist or default to off in older versions.
Anyone know which versions are vulnerable, then? From context I’d guess at least 1803 but could go way back…
-
b
AskWoody_MVPNovember 8, 2018 at 12:46 pm #231464Looks to me like only 1803 (not earlier versions) could possibly have been regarded as vulnerable, and 1809 is not.
But the guy who discovered the bug has now updated his blog entry, and I’m not convinced that he ever considered it to be exploitable:
Update: There has been a bit of misunderstanding on how this works. The broadFileSystemAccess is a restricted capability that an application could be granted, it is not an API. As a developer as well, I have to opt-in to using the capability. Any application in the store with the capability goes through extra verification by the Store team before any user gets it and the user is aware they are granting the application the permission to use the capability as well.
Important information about the new capability of broadFileSystemAccess in UWP apps
-
b
AskWoody_MVPJanuary 17, 2019 at 10:09 am #312781Fixed:
Addresses a privacy issue with apps that obtain the BroadFileSystemAccess capability without a userโs consent.
Viewing 5 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Is it Local or is it Microsoft Account?
by
RetiredGeek
2 hours, 16 minutes ago -
Does Your State Reveal Who’s Been Hacked?
by
Nibbled To Death By Ducks
13 hours, 3 minutes ago -
A one-year extension to Windows 10 โ almost free!
by
Susan Bradley
38 minutes ago -
Windows Configuration Update (KB5062324) โ June 2025
by
Alex5723
26 minutes ago -
A federal judge sides with Anthropic in lawsuit over training AI
by
Alex5723
17 hours, 56 minutes ago -
Name of MS Word Formatting Feature
by
John Baum
6 hours, 44 minutes ago -
InControl Failure?
by
Casey H
5 hours, 6 minutes ago -
Microsoft : Free 1 year support for Windows 10 after EOL
by
Alex5723
6 hours, 48 minutes ago -
MS-DEFCON 3: Businesses must tread carefully
by
Susan Bradley
8 hours, 12 minutes ago -
McLaren Health Care says data breach impacts 743,000 patients
by
Nibbled To Death By Ducks
1 day, 16 hours ago -
WhatsApp banned on House staffers’ devices
by
Alex5723
1 day, 11 hours ago -
Is your device eligible?
by
Susan Bradley
1 day, 19 hours ago -
Windows 11 Insider Preview build 26200.5661 released to DEV
by
joep517
2 days, 2 hours ago -
Windows 11 Insider Preview build 26120.4452 (24H2) released to BETA
by
joep517
2 days, 2 hours ago -
Hello Windows…My Problem is Windows Hello…
by
rdleib
2 days, 3 hours ago -
New Canon Printer Wants Data Sent
by
Win7and10
2 days, 3 hours ago -
I set up passkeys for my Microsoft account
by
Lance Whitney
1 hour, 52 minutes ago -
AI is for everyone
by
Peter Deegan
2 days, 3 hours ago -
Terabyte update 2025
by
Will Fastie
1 day, 21 hours ago -
Migrating from Windows 10 to Windows 11
by
Susan Bradley
4 hours, 33 minutes ago -
Lost sound after the upgrade to 24H2?
by
Susan Bradley
21 hours, 35 minutes ago -
How to move 10GB of data in C:\ProgramData\Package Cache ?
by
Alex5723
1 day, 5 hours ago -
Plugged in 24-7
by
CWBillow
2 days, 12 hours ago -
Netflix, Apple, BofA websites hijacked with fake help-desk numbers
by
Nibbled To Death By Ducks
3 days, 15 hours ago -
Have Copilot there but not taking over the screen in Word
by
CWBillow
3 days, 12 hours ago -
Windows 11 blocks Chrome 137.0.7151.68, 137.0.7151.69
by
Alex5723
5 days, 6 hours ago -
Are Macs immune?
by
Susan Bradley
51 minutes ago -
HP Envy and the Function keys
by
CWBillow
4 days, 14 hours ago -
Microsoft : Removal of unwanted drivers from Windows Update
by
Alex5723
2 days, 7 hours ago -
MacOS 26 beta 1 dropped support for Firewire 400/800
by
Alex5723
5 days, 18 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.