Skip to main content

Complex Passcode Bypass Method Exposes iPhone Contacts and Photos in iOS 12

https://ift.tt/2N98YHN

A passcode bypass vulnerability has been discovered in iOS 12 that potentially allows an attacker to access photos and contact details on a locked iPhone.

The rather convoluted bypass method was shared in a video by Jose Rodriguez, who has discovered iOS bugs in the past that Apple has subsequently fixed.


With physical access to the locked device, the attacker first asks Siri to activate VoiceOver, sleeps the device with the Side button, and then calls the iPhone using another device. Once the call screen shows up, the attacker taps the Message button, opts to create a custom message, and then taps the plus (+) icon in the top right.

Next, on the other phone, the attacker sends a text or iMessage to the target iPhone, whose screen is then double-tapped when the message notification appears. This causes an odd behavior in the UI, since it highlights the plus icon underneath.

After a short wait, the screen goes white and the notification disappears, but the VoiceOver's text selection box is apparently still tappable and can now be used to access the Messages interface. Following multiple screen swipes, the VoiceOver is heard to say "Cancel," which reveals the original Messages screen.


Adding a new recipient to the message and selecting a numeral from the virtual keyboard then reveals a list of recently dialed or received phone numbers and contacts. Further, if one of the numbers or contacts includes an info ("I") button, disabling VoiceOver and tapping the button shows the contact's information. Performing a 3D Touch action on the contact also brings up call and message options, along with options to Add to Existing Contact or Create New Contact.

In a similarly complicated set of steps involving an invisible user menu, an attacker can eventually access a locked iPhone's Camera Roll and other photo folders, which can then be used to add profile pictures to contact cards.

The bypass methods work on all iPhones including the iPhone XS lineup, but Apple doesn't appear to have fixed the vulnerabilities in the latest iOS 12.1 beta. Thankfully however, all of the above can be easily prevented by disabling access to Siri from the lock screen.

Concerned users can do so by navigating to Settings > Face ID & Passcode (that's Settings > Touch ID & Passcode on iPhones with Touch ID) and disabling the Siri toggle under the "Allow access when locked" menu.


Discuss this article in our forums



from MacRumors: Mac News and Rumors - All Stories https://ift.tt/2OXXWqs

Comments

Popular posts from this blog

How to Get a MacBook or MacBook Pro Keyboard Repaired Free Under Apple's Service Program

https://ift.tt/2tocBCJ Apple has initiated a new worldwide service program offering free repairs of MacBook and MacBook models equipped with low-profile, butterfly mechanism keyboards, after the company determined that "a small percentage" of the keyboards may develop one or more of the following issues: Letters or characters repeat unexpectedly Letters or characters do not appear Key(s) feel "sticky" or do not respond in a consistent manner Apple or Apple Authorized Service Providers will service eligible MacBook and MacBook Pro keyboards free of charge. Apple says the process may involve the replacement of one or more keys or the whole keyboard. The following MacBook and MacBook Pro models are eligible for the program: MacBook (Retina, 12-­inch, Early 2015) MacBook (Retina, 12­-inch, Early 2016) MacBook (Retina, 12-­inch, 2017) MacBook Pro (13­-inch, 2016, Two Thunderbolt 3 Ports) MacBook Pro (13-­inch, 2016, Four Thunderbolt 3 Ports) MacBook Pro...

How to like, comment, and add subscribers to shared photo albums on your iPhone, iPad, Mac, or PC

https://ift.tt/2q570On With iCloud Photo Sharing, you can share, like, and comment on photos and videos with friends and family around the world — no social media account needed. Making or subscribing to a shared photo album on iCloud is just the beginning: Once you're part of a shared album with your friends, family, or co-workers, you can add comments, like photos, invite more pals into the fray, and more. iCloud Photo Sharing: The ultimate guide If you want the social media experience without having to plaster your images across the internet, iCloud Photo Sharing offers some great tools for it. Here's how you can like your friends' images, add new people to an existing shared album, and add comment threads to photos and video. How to share albums with people who don't use iCloud How to add someone to a shared photo album How to remove someone from a shared photo album How to let other people add photos and video to your shared photo album How to like...

The Instant Pot Craze and How it's Disrupting Kitchens Everywhere

http://ift.tt/2InTBKj Pressure cooker? Slow cooker? Rice cooker? The Instant Pot is all of these things and more! The Canadian-designed Instant Pot is essentially a roided out slow cooker for half the price of most decent slow cookers on the market. There are several iterations of the Instant Pot, and it may just be able to replace every imaginable kitchen appliance you have. So what's the hubbub? Is the hype real? Let's take a look! See at Amazon What does it do? I think, in terms of kitchen capabilities, the better question is what doesn't the Instant Pot do? The lower-end versions have 6-in-1 functionality, while the Ultra, for example, can be a slow cooker, pressure cooker, rice cooker, yogurt maker, cake maker, egg cooker, sauté cooker, steamer, warmer, and sterilizer. Oh, and the 6-quart Ultra model is only $150 ... Somehow… Basically, the Instant Pot could be your tool for cooker just about everything. With many programmable cooking options, for everyt...