There’s a bug in the UWP API that lets appropriately programmed apps look at all of your data. Günter Born says: (The malicious UWP) app is not limite
[See the full post at: Newly discovered data access breach in Win10 UWP (Metro, “Store”) apps]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Newly discovered data access breach in Win10 UWP (Metro, “Store”) apps
Home » Forums » Newsletter and Homepage topics » Newly discovered data access breach in Win10 UWP (Metro, “Store”) apps
- This topic has 17 replies, 11 voices, and was last updated 6 years, 1 month ago.
Tags: broadFileSystemAccess
AuthorTopicViewing 5 reply threadsAuthorReplies-
WildBill
AskWoody PlusOctober 27, 2018 at 3:03 pm #227597Well, that tears it. Even if Microsoft fixes the bug, I’ll never move to Win10 whatever. Neither Home nor Pro! Yes, I know it will be fixed… but what’s to stop some coder from breaking it again? It’s always been a matter of trust, but MS just lost mine for good when it comes to Windows 10. As long as they don’t break Win8.1 before 2023… bugs start popping up after January 2020, then Linux Mint, here I come!
Bought a refurbished Windows 10 64-bit, currently updated to 22H2. Have broke the AC adapter cord going to the 8.1 machine, but before that, coaxed it into charging. Need to buy new adapter if wish to continue using it.
Wild Bill Rides Again...4 users thanked author for this post.
-
Susan Bradley
ManagerOctober 27, 2018 at 9:45 pm #227629The store process means that apps are vetted so isn’t this a theoretical attack rather than one we will see in reality? It’s like the iPhone bugs that they say “first you have to jailbreak the device”…. well yeah….
Susan Bradley Patch Lady/Prudent patcher
1 user thanked author for this post.
-
anonymous
Guest -
Susan Bradley
ManagerOctober 28, 2018 at 1:55 am #227642
-
-
-
Jan K.
AskWoody Lounger -
lurks about
AskWoody LoungerOctober 28, 2018 at 9:25 am #227670What I understood was the problem is UWP apps were granted extensive file reading (writing?) privileges even when the developer did not invoke them or request them. Thus it sounds like a carefully crafted app could harvest files from anywhere on the box and send them to their mothership. How practical this mode would be; I do not know.
1 user thanked author for this post.
-
anonymous
GuestSeff
AskWoody PlusOctober 27, 2018 at 3:21 pm #227601Surely not! Windows 10 is the most secure version of Windows, is it not?
Thanks for the info, Woody.
2 users thanked author for this post.
-
Charlie
AskWoody Plus
lanceboil
AskWoody Loungerb
AskWoody_MVPOctober 27, 2018 at 6:18 pm #227618There’s a bug in the UWP API that lets appropriately programmed apps look at all of your data.
But there are unlikely to be any such apps (apart from Microsoft’s App Installer and Diagnostics Data Viewer) because;
If you submit an app to the Store that declares this capability, you will need to supply additional descriptions of why your app needs this capability, and how it intends to use it.
Docs / Windows / UWP / Develop / Files, folders, and libraries / File access permissionsAnd the capability can be disabled per device, per user or per app.
As for the app crash on 1809; that sounds like a programmer error:
Some capabilities provide apps with access to a sensitive resource. These resources are considered sensitive because they can access the user’s personal data or cost the user money. Privacy settings, managed by the Settings app, let the user dynamically control access to sensitive resources. Thus, it’s important that your app doesn’t assume a sensitive resource is always available.
Docs / Windows / UWP / Develop / Packaging apps / App capability declarations1 user thanked author for this post.
-
woody
Manager
mn–
AskWoody LoungerOctober 29, 2018 at 3:14 am #227837… so, let’s see…
1. UWP apps from outside the Store have direct filesystem access on by default in previous versions of Windows 10, but off by default in 1809. The bug is that the permission dialog doesn’t display automatically on first instance of the specific app requiring this permission.
2. UWP apps that need direct filesystem access and don’t have it, throw an exception that defaults to crashing the app unless caught. The permission state can change while app is running and takes effect immediately.
Now, unless there’s something even weirder going on, surely the user’s UWP apps still run in the normal user context and thus only have at most as much capability as the user’s non-UWP processes, thus not causing any inherent extra risk just due to being UWP? Such as in this case with a business-specific internal app, apparently…?
What I find potentially somewhat risky is the unexpected state change, which logically might prevent the app from saving its data to disk, thus having the potential for data loss. This is not markedly different from non-UWP apps running into an unexpected permissions problem at file open time but might differ for files that were already open, or does the UWP platform prevent continuously open files or something?
Not going into whatever may be going on with the Store – the “vetting” processes would reduce risks but not eliminate.
-
mn–
AskWoody LoungerOctober 29, 2018 at 8:23 am #227856… hm, it seems that the “broad filesystem access” privacy settings entry just isn’t there at all in at least W10 1709…
Now, from https://stackoverflow.com/questions/49728846/uwp-c-sharp-folderpicker-without-dialog and elsewhere, broad filesystem access was supposed to either not exist or default to off in older versions.
Anyone know which versions are vulnerable, then? From context I’d guess at least 1803 but could go way back…
-
b
AskWoody_MVPNovember 8, 2018 at 12:46 pm #231464Looks to me like only 1803 (not earlier versions) could possibly have been regarded as vulnerable, and 1809 is not.
But the guy who discovered the bug has now updated his blog entry, and I’m not convinced that he ever considered it to be exploitable:
Update: There has been a bit of misunderstanding on how this works. The broadFileSystemAccess is a restricted capability that an application could be granted, it is not an API. As a developer as well, I have to opt-in to using the capability. Any application in the store with the capability goes through extra verification by the Store team before any user gets it and the user is aware they are granting the application the permission to use the capability as well.
Important information about the new capability of broadFileSystemAccess in UWP apps
-
b
AskWoody_MVPJanuary 17, 2019 at 10:09 am #312781Fixed:
Addresses a privacy issue with apps that obtain the BroadFileSystemAccess capability without a user’s consent.
Viewing 5 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Hacktool:Win32/Winring0 (Awaiting moderation)
by
Marvel Wars
1 hour, 39 minutes ago -
Google’s 10-year-old Chromecast is busted, but a fix is coming
by
Alex5723
3 hours, 34 minutes ago -
Expand the taskbar?
by
CWBillow
3 hours, 24 minutes ago -
Gregory Forrest “Woody” Leonhard (1951-2025)
by
Susan Bradley
1 hour, 37 minutes ago -
March 2025 updates are out
by
Susan Bradley
13 hours, 7 minutes ago -
Windows 11 Insider Preview build 26120.3380 released to DEV and BETA
by
joep517
21 hours, 10 minutes ago -
Update Firefox to prevent add-ons issues from root certificate expiration
by
Alex5723
1 day, 4 hours ago -
Latest Firefox requires Password on start up
by
Gordski
22 hours, 53 minutes ago -
Resolved : AutoCAD 2022 might not open after updating to 24H2
by
Alex5723
1 day, 17 hours ago -
Missing api-ms-win-core-libraryloader-11-2-1.dll
by
IreneLinda
15 hours, 55 minutes ago -
How Much Daylight have YOU Saved?
by
Nibbled To Death By Ducks
18 hours, 53 minutes ago -
A brief history of Windows Settings
by
Simon Bisson
12 hours, 31 minutes ago -
Thunderbolt is not just for monitors
by
Ben Myers
11 hours, 7 minutes ago -
Password Generators — Your first line of defense
by
Deanna McElveen
16 hours, 34 minutes ago -
AskWoody at the computer museum
by
Will Fastie
12 hours, 10 minutes ago -
Planning for the unexpected
by
Susan Bradley
17 hours, 34 minutes ago -
Which printer type is the better one to buy?
by
Bob99
1 day, 18 hours ago -
Upgrading the web server
by
Susan Bradley
1 day, 17 hours ago -
New Windows 11 24H2 Setup – Initial Win Update prevention settings?
by
Tex265
2 days, 12 hours ago -
Creating a Google account
by
DavidofIN
2 days, 11 hours ago -
Undocumented “backdoor” found in Bluetooth chip used by a billion devices
by
Alex5723
2 days, 17 hours ago -
Microsoft Considering AI Models to Replace OpenAI’s in Copilot
by
Alex5723
3 days, 4 hours ago -
AI *emergent misalignment*
by
Alex5723
3 days, 5 hours ago -
Windows 11 Disk Encryption/ Bitlocker/ Recovery Key
by
Tex265
1 day, 13 hours ago -
Trouble signing out and restarting
by
Tech Hiker
12 hours, 58 minutes ago -
Windows 7 MSE Manual Updating
by
Microfix
9 hours, 45 minutes ago -
Problem running LMC 22 flash drive
by
Charlie
2 days, 13 hours ago -
Outlook Email Problem
by
Lil88reb
2 days, 13 hours ago -
“Microsoft 365 Office All-in-One For Dummies, 3rd Edition FREE
by
Alex5723
2 days, 20 hours ago -
Cant use Office 2013 – Getting error message about Office 2013
by
SAAR
3 days, 13 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.