Skip to main content

iOS 7 flaw bypasses lock screen, lets anyone access your contact list

posted onMay 8, 2014
by l33tdawg

Security issues with iOS 7 seem to be popping up everywhere. Last week, we reported that iOS 7 suffered from a bug which left email attachments unencrypted -- and while Apple has prepared a fix for the issue, a new one has appeared in its place.

According to Egyptian neurosurgeon and part-time security researcher Sherif Hashim, a flaw in iOS 7's Siri voice assistant allows anyone to bypass the iPhone lock screen and access the contact list. In a video posted on his YouTube channel, Hashim detailed the method of attack.

Using an iPhone 5S, Hashim tries and fails to sign in with the TouchID fingerprint scanner. Then, he activates Siri and accesses the phone's contact list by saying "contacts." Siri responds that he needs to unlock the phone first, but Hahim quickly hits cancel and instructs Siri to call a contact. This brings up the phone's entire contact list, which allows Hashim to view and call anyone on the list.

Source

Tags

iOS Security Apple

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th