Skip to main content

Apple fixes bug that let Siri bypass passcode to access Contacts and Photos

No ask for passcode, Siri gives access contacts and photos. iOS 9 - 9.3.1 & iPhone 6S 6S+ (3D Touch)
Apple has fixed a security flaw that let Siri access Contacts and Photos from the lockscreen for devices running iOS 9 and above.

The vulnerability was discovered by YouTuber Jose Rodriguez, and only affects the iPhone 6S and the 6S Plus as it involves 3D Touch. In the video, Rodriguez initiates a Twitter search via the “Hey Siri” feature, without unlocking the phone. His search of a contact brought up contact information, allowing him to press down on it with 3D Touch to bring up a Quick Actions menu.

Recommended Videos

The Daily Dot found that you can ask Siri to search Twitter for “@gmail.com” or any other second half of an email address to pull up a contact’s informatiom. When you see a tweet with an email address, that’s when you can bring up the Quick Actions menu.

Rodriguez then taps “Add to Existing Contact,” which brings up his entire Contacts list, and he follows that by tapping on a contact and hitting “Add Photo,” which then offers full access to his photo library.

Essentially, Rodriguez shows the flaw could offer someone else using a locked device access to Twitter contact information, your contacts, and your photos. Do note that it’s only possible to access if you have granted Siri access to Contacts, Photos, or Twitter account information.

It also seemed to vary as to whether you can access this Twitter search without providing a passcode — most of the time Siri asked for a passcode, but some times it randomly went ahead with the search.

An Apple spokesperson says the issue was fixed this morning, and the fix is rolling out server side globally.

If you’re still wary, you can turn off Siri’s access to search Twitter by heading to Settings, finding Twitter, and toggling Siri off.

Julian Chokkattu
Former Digital Trends Contributor
Julian is the mobile and wearables editor at Digital Trends, covering smartphones, fitness trackers, smartwatches, and more…
If you have an iPhone, you need to download iOS 18 ahead of Hurricane Milton
Satellite messaging features on an iPhone with iOS 18.

Florida is preparing for Hurricane Milton's arrival on Wednesday. As the storm approaches, here's a valuable tip for iPhone users in its path.

Before the storm's arrival, it's crucial to download iOS 18 on your iPhone. With this version of iOS 18 installed, you immediately gain access to Apple's new Messages via satellite feature. The new feature lets you send and receive text messages without cellular and Wi-Fi coverage. This means you can stay connected with friends, family, and emergency services even in areas where power might be lost.

Read more
Apple Intelligence is right around the corner, with a few absent perks
Apple Intelligence update on iPhone 15 Pro Max.

Back in September. Apple announced that its suite of next-gen AI features would make their way to supported hardware in October. Today, Bloomberg reports that rollout of those AI features – clubbed under the Apple Intelligence banner – will begin on October 28.

The AI toolkit will arrive with the iOS 18.1 update for the iPhone 15 Pro pair, the entire iPhone 16 series, and iPads with M1 (or newer) silicon in the series. Unfortunately, this is not the full Apple Intelligence package that the company announced a while ago.

Read more
The first iOS 18 update fixes a major bug with Apple’s Passwords app
An iPhone showing the Apple Password app.

Apple has finally introduced iOS 18.0.1 and iPadOS 18.0.1, the first software updates for iOS 18 and iPadOS 18. Although this iOS 18.1, which will brng the Apple Intelligence update that many have been waiting for, it’s important nonetheless.

The iOS 18.0.1 update fixes a pesky bug in Apple’s new Password app. As the iOS 18.0.1 change notes explain, there was an issue where the Password app could inadvertently use VoiceOver to read out passwords. No doubt, this is a bug no one wants to see, and now it’s squashed.

Read more