Sunday, December 23, 2018

Pocket App for iOS - Can't seem to dismiss the "Legal & Privacy" pop up

Pocket app for iOS (version 7.0.10)
Date: 12/23/2018

Description:

I cannot seem to dismiss the "Legal & Privacy" pop up. I wasn't able to dismiss it on either my iPad Mini, or with an iPhone.

This is easier to show than it is to describe, so please take a look at the embedded tweet below:



Steps to reproduce:
1. Download the Pocket app for iOS (version 7.0.10)
2. Launch the app - Create a new account
3. Head to the "Profile" page
4. Select the gear for settings in the upper right
5. From the "Options" pop up, scroll down and select "Legal & Privacy"
6. Press "Back" to try to back out of the "Pocket: Legal" pop up

Result: I seemingly can't back out of the "Pocket: Legal" pop up on either my iPad Mini or an iPhone

Expected: I should be able to back out/the "back" button should work, on the "Pocket: Legal" pop up

Sunday, December 16, 2018

Flora - Build Better Habits App. Automatically has read access to camera roll

Flora - Build Better Habits app for iOS (version 1.02)
Date: 12/17/18

Description:

The Flora - Build Better Habits app for iOS appears to have full access to the camera roll without asking for permission. I don't believe this is allowed, and that a dialog message requesting access is required. I know that there is an exemption for profile photos, but the Flora app accesses the complete camera roll without any message from other areas of the app.

It specifically accesses them from the "Connect" screen, after the user clicks inside of the "What do you want to say?" input box, and then clicks on the camera icon. After doing this, the app appears to have full access to the camera roll, without having displayed a permissions prompt.

This is easier to show than it is to describe, so please see the attached screenshots.

Steps to Reproduce:

1. Download and launch the Flora - Build Better Habits app for iOS
2. Create a brand new account
3. Select the message dialog image on the bottom of the screen
4. From the "connect" screen, click inside the "What do you want to say?" input box
5. From the keyboard, select the camera icon

Result: The Flora - Build Better Habits app for iOS appears to have access to camera roll by default. There is no permission message when the app first accesses the camera roll

Expected: That the Flora - Build Better Habits app for iOS will display a permission message before accessing the camera roll

Create a new account...

Click on the messages icon...

Click inside of "What do you want to say?"

Click on the camera icon...

Access to the camera roll is granted (where was the permissions message?)

If the app has read access, why isn't it listed here?


Sunday, December 9, 2018

TeachX Mobile App - No User Permission Prompt When Accessing the Camera Roll

TeachX Mobile app for iOS (version 1.0.4)
Date: 12/10/2018

Description:

The TeachX app does not prompt the user permission's to access the camera roll. This happens if the user selects the camera or camera roll option from messages area.

While I believe that this is allowed for profile pictures, I do not believe that this is allowed in any other area of an app.

This is easier to show than it is to describe, so please see the attached screenshots.

Steps to Reproduce:

1. Download and launch the TeachX Mobile app
2. Create an account - approve the EULA
3. Once inside the app, select "Messages"
4. Click on the top right hand of the screen for a "New Message"
5. Enter in a letter, choose any person
6. Click on the button below the garbage can
7. Select either the camera or camera roll option

Result: The TeachX Mobile app opens up and has access to the camera roll without a permission prompt to the user

Expected: The TeachX Mobile app should display a permission prompt to the user before accessing the camera roll

As you can see, no access is indicated on the permissions screen.

Select the Messages option, and send a message. I sent one to myself, so as to not bother regular users...

Click the option in the bottom left hand corner of the screen. Select either the camera icon, or the camera roll icon...

Access to camera roll without read permission asked for, or granted.


Bennett's Mill Middle School App - Un-muting the "Volunteer Mandated Reporter Training Video" crashes the app

Bennett's Mill Middle School App for iOS (version 1.0.7)
Date: 12/09/2018

Description:

The Bennett's Mill Middle School App crashed repeatedly (7+ times) on my iPad Mini when I went in to view the "Volunteer Mandated Reporter Training Video".

This video starts with the audio off by default. It also immediately enters into full screen by default. If you exit out, and then tap the un-mute pop up. The app crashes frequently.



Steps to Reproduce:

1. Launch the Bennett's Mill Middle School app
2. Select the side bar slider
3. Select "Parent Resources"
4. Select "Volunteer Training"
5. Select "View this Video"
6. From the "Volunteer Mandated Reporter Training Video" (with that text on screen) exit out of the full screen mode
7 Toggle the un-mute option

Result: The app frequently crashes if you un-mute the audio on the "Volunteer Mandated Reporter Training Video" that is linked through the "Volunteer Training" portion of the "Parent Resources" section of the app

Expected: The Bennett's Mill Middle School app shouldn't crash if you un-mute the audio on the "Volunteer Mandated Training Video"

NOTE: I know this could be a YouTube problem, but I frequently do this (exit out of full screen, un-mute videos, etc.) and had not seen this happen often until I tried with the Bennett's Mill Middle School App

Saturday, December 1, 2018

The Truth Comes Out Game for iOS - Missing word on permission page

The Truth Comes Out game for iOS (version 1.0.8)
Date: 12/01/2018

Description:

The new The Truth Comes Out game for iOS has an extremely minor issue on

Steps to Reproduce:

1. Download and launch The Truth Comes Out
2. Look at link for "Terms of"

Result: There looks to be a missing word on The Truth Comes Out intro screen

Expected: It should say "Terms of Use"

Please see attached screenshot. Thanks.





Sunday, November 25, 2018

Wayfair App - iOS - declining photo library access and then pressing on photo button will crash the app

Wayfair app for iOS (version 4.59)
Date: 11/25/2018

Description:

The Wayfair app for iOS will crash on my iPad Mini if I decline photo access and then click on the phone button. This is a rare one, as I frequently play around with this on every app that I download.



Steps to reproduce:

1. Download the Wayfair app for iOS
2. Launch it
3. Select the camera option in upper right
4. Decline photo library access
5. Click the button above "Try with a Wayfair Photo"

Result: The Wayfair app will crash if the user declines photo access, and then presses the photo button

Expected: The Wayfair app (version 4.59) should not crash if the user declines photo access and then presses the photo button


Thursday, November 22, 2018

Text on the “Cancel” and “Settings” confirmations buttons on Photo/Camera permissions page

ReadSelf app for iOS (version 4.22.0)
Date: 11/22/2018


Description:

The text on some confirmation buttons does not appear.

This is the text of the words "Cancel" and "Settings" on the confirmation buttons on the photos permission page.




Steps to reproduce:

Download the app > create an account
Choose something you’re interested in
After the “Personalizing your home feed…” animation finishes, select “Me”
Select “Reviews”
Select the camera option
Select “Don’t Allow” from the three pop ups

Result: There is frequently no text inside of the “Cancel” and “Settings” buttons on the photo/video permissions page

Expected: There should be text inside of the “Cancel” and “Settings” buttons on the photo/video permissions page



Thursday, November 15, 2018

Royal Farms Rewards - UI - Simultaneously tapping "Back" and "Info" causes to the top UI options to disappear

Royal Farms Rewards app for iOS (version 2.1)
Date: 11/15/2018

Description:

There is a minor bug with the Royal Farms Rewards app for iOS. There is an easy way to make a portion of the user interface disappear.

This is much easier to show than it is to describe, so please just take a look at the attached screenshots.

While this bug would most likely never occur in regular use, it is similar to other bugs that occasionally happen with other iOS apps.



Steps to Reproduce:

1. Download and launch the Royal Farms Rewards app for iOS (version 2.1)
2. Dismiss the notifications pop up
3. Dismiss the location pop up
4. Select "Skip" to get through the tutorial
5. Select "Continue as Guest"
6. Select the "View All" option to from the Rewards slider
7. Dismiss the pop up
8. From the rewards page, double tap simultaneously on "Back" and "Info"
9. User will be taken to a "Rewards Info" page with a "<Back" in the upper right
10. Select "<Back"

Result: There is an easy way to get portions of the top user interface to disappear from within the Royal Farms Rewards iOS app - this occurs when the user simultaneously taps on

Expected: Portions of the user interface should not disappear from inside of the Royal Farms Reward iOS app

Select "Continue as Guest..."

Select "View All"

Dismiss the pop up...

Double tap on "<Back" and "Info" at the same time...

The user will be taken to this page. Now click on "<Back"...


The top UI has now disappeared....

Wednesday, October 31, 2018

Bed Bath & Beyond - Account Creation - Misleading Error Message

Bed Bath & Beyond app for iOS (version 7.5.2)
Date: 10/31/2018

Description:

There is a misleading error message during account creation on the Bed Bath & Beyond iOS app. While this problem/bug is extremely minor, I actually think that it is pointing to another bug, which could be worse - at least from the point of view of having a smooth account creation process.

This is easier to show than it is to describe, so please see the attached screenshots.

The user is prohibited from entering in an apostrophe in the Last Name field during the sign up process. This wouldn't be a big deal, except that if the user tries to enter in a Last Name with an apostrophe, a big red error message appears that says, "Please enter letters, apostrophes, hyphens, and spaces only."

The error message specifically tells me that apostrophes are allowed - so why am I seeing this error message.

Also, oddly, the automatically generated email suggestion field pops up as soon as I click in the "Last Name" input box. Isn't this supposed to show up from the email input box at the top of the page? Was the email input box moved to the top of the screen, but the keyboard still thinks it is in third position?

Just a little frustrating for the user!


Steps to Reproduce:
1. Download and launch the Bed Bath & Beyond app for iOS (version 7.5.2)
2. Select "More" from the bottom UI
3. Select "Create Account"
4. From the "Create Account" page enter in a valid email
5. From the "Create Account" page enter in a valid First Name
6. From the "Create Account" page, click inside the Last Name input box (note that the auto-generated, saved email feature pops up at this point. Which is weird)
7. Inside of the Last Name input box, enter in an Irish name like "O'connor"
8. After hitting next to advance to the password input box, note the error message, "Please enter letters, apostrophes, hyphens, and spaces only"
9. Scratch your head and wonder why "O'connor" isn't acceptable as a last name

Result: User is apparently prohibited from using a last name with an apostrophe in it, even though an error message message claims that it is allowed

Expected: Either the user should be allowed to have a last name with an apostrophe, or the error message should be amended to state that apostrophe's aren't allowed

After launching the app, click on "More"...

Enter in a name like "O'Connor" into the last name input box. The error message tells me that apostrophes are allowed...

In addition - it gets stranger! When I first click into the Last Name input box, the auto generated email thing in the keyboard shows up. Instead of when I first click in the email input box. Frustrating!

Thursday, October 25, 2018

Sky News iOS app - Twitter Sharing - No links to articles

Sky News app for iOS (version 4.11.1)
Date: 10/26/2018

Description:

Twitter sharing from the Sky News iOS app to Twitter doesn't work. It only shares an image and headline related to an article, not a link to it. Loss of potential traffic to the site.

Easier to show than to describe, so please see the attached screenshots.

Steps to Reproduce:

1. Download the Sky New iOS app (version 4.11.1)
2. Go to the most recent article
3. Click on the iOS share option in upper right
4. Select the twitter option
5. Note that generate tweet only has headline and picture - no link to article

Result: No links to articles in tweets

Expected: Links to articles in tweets

Select an article...

Select the twitter share icon...

No link to article.

Thursday, October 18, 2018

Victoria's Secret app: XSS: A plaintext search results in a cross site scripting error

Victoria's Secret app for iOS (version 5.4.2)
Date: 10/18/2018

Description:

The most common self-reflecting XSS bug is active with the Victoria's App for iOS.

If the user searches for "<plaintext>" in the search box, the app barfs up HTML.

Easier to show than to describe, so please see the attached screenshots.

Steps to Reproduce:

1. Download and launch the Victoria's Secret app for iOS (version 5.4.2)
2. Click on "SHOP"
3. Click inside the magnifying glass to search
4. Enter in <plaintext> as a search term
5. Run a search

Result: There is an cross site scripting error if the user runs a search for "<plaintext>"

Expected: There should not be a cross site scripting error if the user runs a search for "<plaintext>"

Launch the app, then click on "SHOP"...

Click on the magnifying glass...

Run a search in this search box...

Enter in <plaintext> as a search term...

Barfs HTML.

Tuesday, October 9, 2018

JCPenney - Account Creation - The "Next" keyboard button doesn't advance the user

JCPenney App for iOS (version 8.9.2)
Date: 10/10/2018

Description:

On the "Create Account" screen, the "Next" button doesn't advance the user to the next input box. This is very noticeable!

This is easier to show than to describe, so please take a look at the attached screenshots.

Steps to Reproduce:

1. Download and launch the JCPenney App for iOS
2. Advance to the "Create Account" screen
3. Click inside the "First Name" input box
4. Enter in a valid first name
5. Click "Next" on the keyboard

Result: The "Next" button on the keyboard does not advance the user to the next input box on the "Create Account" screen

Expected: The "Next" button on the keyboard should advance the user to the next input box on the "Create Account" screen

Download and launch the JCPenney app (version 8.9.2)

Select the "Create Account" button...

The "Next" button on the keyboard doesn't advance the user to the next input box.

Friday, October 5, 2018

Shopbop app - Pressing "Shop by Category" and "Shop What's New" at the same time crashes the app

Shopbop App for iOS (version 3.1.1)
Date: 10/05/2018

Description:

There is an easy way to crash the Shopbop app for iOS.

Within the app there is a shopping bag icon in the upper right hand corner of the screen. After selecting this icon, you are taken to a "Shopping Bag" page. On the "Shopping Bag" page there are two options. One of these options is "Shop by Category" while the other is "Shop What's New."

If you press both of these options at the same time, the app will crash. This happens every time it is is done. I will attached a crash dump.

This is easier to show than it is to describe, so please see the attached screenshots.

Steps to Reproduce:

1. Download and launch the Shopbop app for iOS
2. Select the shopping bag icon in the upper right hand corner of the screen
3. Press and hold "Shop by Category" and "Shop What's New" simultaneously
4. Release "Shop by Category" and "Shop What's New" simultaneously

Result: Pressing, holding, and then releasing "Shop by Category" and "Shop What's New" on the Shopping Bag page crashes the app

Expected: Pressing, holding, and then releasing "Shop by Category" and "Shop What's New" simultaneously should not crash the app

Select the Shopping Bag option in the upper right...

Press "Shop by Category" and "Shop What's New" at the same time...

The app will then crash.

Here is the crash dump:


Wednesday, September 12, 2018

Inky App - Account Creation - Trailing Whitespaces - Cannot Complete Account Creation if there is a trailing whitespace behind a valid email address

Inky app for iOS (Version 1.0.26)
Date: 09/12/2018

Description:

It is impossible to complete non-Facebook account creation if there is a trailing whitespace behind a valid email address during the sign up process.

This is easier to show than it is to describe, so please see the attached screenshots.

Steps to Reproduce:

1. Download and launch the Inky app for iOS
2. Select "Sign up"
3. From the "Create Account" page, enter in a valid email address
4. Behind the valid email address, press the spacebar once
5. Enter in a password and confirm
6. Click on "Next"
7. Approve the Terms of Use

Result: During the account creation process, entering in a space behind a valid email address prohibits the user from creating account

Expected: The trailing whitespace should be automatically corrected - should not result in an error message

Enter in a valid email address...

Enter in a single space after the valid email address...

Approve the Terms of Use...

Note the error message. 

Tuesday, May 15, 2018

Newsmax app - Share option crashes the app

Date: 05/15/2018
iPad Mini iOS: 11.2.6 (build 15D100)
Newsmax - app version 2.0.3

Description:

The Newsmax app for iOS crashes on my iPad Mini every time the "Share" option is selected.

Please see the attached screenshots.

Steps to Reproduce:

1. Launch the Newsmax app (version 2.0.3) on an iPad Mini
2. Select any option (like "health")
3. Select the "Share" option in upper right hand corner

Result: Selecting the "Share" option in the Newsmax app on my iPad Mini crashes the app

Expected: Selecting the "Share" option from within the Newsmax app should not crash the app


Launch the Newsmax app on an iPad Mini...

Select an option like "Health"...

Select the "Share" option in the upper right. The app will crash.

Wednesday, February 21, 2018

REI - Shop Outdoor Gear - blank png image icons for sharing

Date: 02/22/2018
iPad Mini iOS: 11.2.6
REI - Shop Outdoor Gear app version: 6.0.2

Description:

On my iPad Mini, the REI - Shop Outdoor Gear app has a minor bug.
On the share option for any product the share options that appear lack the appropriate png image icons.

The Message/Mail/Add to Notes/Facebook/Messenger/Twitter options are all blank.
This is a bug I have seen a couple times before, and from what I understand, it is easy to fix.

Please see the attached screenshots.

Steps to Reproduce:

1. Download the app
2. Go to any product
3. Select the share icon

Result: The share options that appear on the REI - Shop Outdoor Gear app are all blank -
they are missing the appropriate png image icons

Expected: On my iPad Mini, while using the REI - Shop Outdoor Gear app,
I expect to see the appropriate png image icons for sharing

Download the REI - Shop Outdoor Gear app on an iPad Mini

Launch the app
Head to any product (creating an account or signing in isn't necessary)

Head to any item
Select the "Share" option
Blank image icon 

Thursday, February 8, 2018

Tictail - blank png image icons for sharing

Date: 02/08/2018
iPad Mini iOS version: 11.0
Tictail app Version: 2.12.14

Description:

On my iPad Mini, the Tictail app (version 2.12.14) has a minor bug. On the share option for any item, the sharing options that appear lack the appropriate png image icons.

Meaning, Message/Mail/Reminders/Add to Notes/Facebook/Messenger/Twitter are all blank. I have only seen this happen a few times with iOS apps on the iPad Mini. This does NOT reproduce with the Tictail app on an iPhone.

It is easier to show than to describe, so please see the attached screenshots.

Steps to Reproduce:

1. Download and launch the Tictail app on an iPad Mini
2. Select any item
3. Select the share option

Result: The Message/Mail/Reminders/Add to Notes/Facebook/Messenger/Twitter options are all blank (no png images for these options) with the Tictail app on an iPad Mini

Expected: That the Message/Mail/Reminders/Add to Notes/Facebook/Messenger/Twitter options will appear

Launch the app, select any item...

Select the share option in the upper right...

No image png icons for things like Facebook, Messenger, Twitter...