Skip to main content

Apple fixes bug that let Siri bypass passcode to access Contacts and Photos

No ask for passcode, Siri gives access contacts and photos. iOS 9 - 9.3.1 & iPhone 6S 6S+ (3D Touch)
Apple has fixed a security flaw that let Siri access Contacts and Photos from the lockscreen for devices running iOS 9 and above.

The vulnerability was discovered by YouTuber Jose Rodriguez, and only affects the iPhone 6S and the 6S Plus as it involves 3D Touch. In the video, Rodriguez initiates a Twitter search via the “Hey Siri” feature, without unlocking the phone. His search of a contact brought up contact information, allowing him to press down on it with 3D Touch to bring up a Quick Actions menu.

Recommended Videos

The Daily Dot found that you can ask Siri to search Twitter for “@gmail.com” or any other second half of an email address to pull up a contact’s informatiom. When you see a tweet with an email address, that’s when you can bring up the Quick Actions menu.

Please enable Javascript to view this content

Rodriguez then taps “Add to Existing Contact,” which brings up his entire Contacts list, and he follows that by tapping on a contact and hitting “Add Photo,” which then offers full access to his photo library.

Essentially, Rodriguez shows the flaw could offer someone else using a locked device access to Twitter contact information, your contacts, and your photos. Do note that it’s only possible to access if you have granted Siri access to Contacts, Photos, or Twitter account information.

It also seemed to vary as to whether you can access this Twitter search without providing a passcode — most of the time Siri asked for a passcode, but some times it randomly went ahead with the search.

An Apple spokesperson says the issue was fixed this morning, and the fix is rolling out server side globally.

If you’re still wary, you can turn off Siri’s access to search Twitter by heading to Settings, finding Twitter, and toggling Siri off.

Julian Chokkattu
Former Digital Trends Contributor
Julian is the mobile and wearables editor at Digital Trends, covering smartphones, fitness trackers, smartwatches, and more…
I compared Apple’s and Samsung’s AI photo editing tools. There’s a clear winner
The Samsung Galaxy S24 Ultra and Apple iPhone 16 Pro Max's screen.

Apple has joined the AI game with Apple Intelligence, finally catching up to its competitors in that department. And with the iOS 18.1 update in October, most people who have a compatible iPhone can finally use those Apple Intelligence tools, including Clean Up.

The Clean Up tool in the Photos app is basically Apple’s version of Google’s Magic Eraser or Samsung’s Object Eraser. Back when I compared Magic Eraser and Object Eraser, Samsung’s tool was the better of the two. So, how does Apple’s Clean Up compare? Let’s find out.
The limitations of object removal tools

Read more
I hate the new Photos app in iOS 18
Photos app on iOS 18.

When Apple launched the iPhone 16 line, it also released iOS 18 to the masses after months of betas. Though the biggest feature of iOS 18 is Apple Intelligence, which didn’t actually launch until the iOS 18.1 release, there are plenty of other things that iOS 18 brings to the table. That includes RCS messaging, more home screen customization, a revamped Control Center, and more.

One app that got a significant redesign in iOS 18 is the Photos app. After around a decade of mostly the same design and what I would call muscle memory, the new Photos app is, well, quite jarring — and I'm not a fan.
The new Photos app is messy
The old Photos app Christine Romero-Chan / Digital Trends

Read more
A hidden iOS 18.1 upgrade made it harder to extract data from iPhones
A person holding the Apple iPhone 16 Plus.

Apple Intelligence was the most notable upgrade that arrived on iPhones with the iOS 18 series of updates. But it seems Apple reinforced the security protocols in the background that could prevent bad actors from gaining unauthorized access to iPhones that haven’t been unlocked in a while by their legitimate owner.

Earlier this month, 404Media reported that law enforcement officials are troubled by iPhones that are mysteriously rebooting. Citing a report courtesy of officials in Michigan, the outlet notes that the reboots are hampering the ability to access what’s stored on the phones through brute-force unlock methods.

Read more