Skip to main content

Apple fixes bug that let Siri bypass passcode to access Contacts and Photos

No ask for passcode, Siri gives access contacts and photos. iOS 9 - 9.3.1 & iPhone 6S 6S+ (3D Touch)
Apple has fixed a security flaw that let Siri access Contacts and Photos from the lockscreen for devices running iOS 9 and above.

The vulnerability was discovered by YouTuber Jose Rodriguez, and only affects the iPhone 6S and the 6S Plus as it involves 3D Touch. In the video, Rodriguez initiates a Twitter search via the “Hey Siri” feature, without unlocking the phone. His search of a contact brought up contact information, allowing him to press down on it with 3D Touch to bring up a Quick Actions menu.

Recommended Videos

The Daily Dot found that you can ask Siri to search Twitter for “@gmail.com” or any other second half of an email address to pull up a contact’s informatiom. When you see a tweet with an email address, that’s when you can bring up the Quick Actions menu.

Rodriguez then taps “Add to Existing Contact,” which brings up his entire Contacts list, and he follows that by tapping on a contact and hitting “Add Photo,” which then offers full access to his photo library.

Essentially, Rodriguez shows the flaw could offer someone else using a locked device access to Twitter contact information, your contacts, and your photos. Do note that it’s only possible to access if you have granted Siri access to Contacts, Photos, or Twitter account information.

It also seemed to vary as to whether you can access this Twitter search without providing a passcode — most of the time Siri asked for a passcode, but some times it randomly went ahead with the search.

An Apple spokesperson says the issue was fixed this morning, and the fix is rolling out server side globally.

If you’re still wary, you can turn off Siri’s access to search Twitter by heading to Settings, finding Twitter, and toggling Siri off.

Julian Chokkattu
Former Digital Trends Contributor
Julian is the mobile and wearables editor at Digital Trends, covering smartphones, fitness trackers, smartwatches, and more…
iOS 17: Apple didn’t add the one feature I’ve been waiting for
Multiwindow on Galaxy S23 Ultra (on left) and multiwindow with popup window on Oppo Find X6 Pro (on right).

Multiwindow on the Samsung Galaxy S23 Ultra (left) and multiwindow with pop-up window on the Oppo Find X6 Pro (right). Prakhar Khanna/Digital Trends

I’m a big-screen phone advocate. While I like the comfort of holding a compact phone (such as the Samsung Galaxy S23 with a 6.1-inch display), I prefer using devices like the Galaxy S23 Ultra, Oppo Find X6 Pro, Xiaomi 13 Pro, and iPhone 14 Pro Max.

Read more
iOS 17 isn’t the iPhone update I was hoping for
iMessage stickers in iOS 17

Apple gave us a jam-packed WWDC 2023 keynote, and it was one of the most significant ones in years. After all, it introduced a brand new product category for Apple with the Vision Pro mixed reality headset. It’s basically as significant as when Steve Jobs revealed the iPhone in 2007, then the iPad in 2010, and when Tim Cook showed off the Apple Watch in 2014.

But the headset isn’t the only thing we got in the WWDC keynote. Since it’s a developer conference, it’s also about the software for all of our devices. This includes iOS 17 for the iPhone, along with iPadOS 17, watchOS 10, and macOS 14 Sonoma.

Read more
iOS 17’s coolest new feature is horrible news for Android users
iOS 17 contact posters

At the end of 2022, Google implored Apple to “get the message” and end the green-versus-blue bubble controversy by adopting RCS messaging. Apple’s response eventually came at WWDC 2023, where it introduced a new iOS 17 feature called Contact Posters, which instead of bringing everyone together, only furthers the us-versus-them split between Android and iOS.

If you thought the green/blue iMessage arguments could get fiery, there’s a lot more to come.
Blue good, green bad

Read more