Skip to main content

Apple fixes bug that let Siri bypass passcode to access Contacts and Photos

No ask for passcode, Siri gives access contacts and photos. iOS 9 - 9.3.1 & iPhone 6S 6S+ (3D Touch)
Apple has fixed a security flaw that let Siri access Contacts and Photos from the lockscreen for devices running iOS 9 and above.

The vulnerability was discovered by YouTuber Jose Rodriguez, and only affects the iPhone 6S and the 6S Plus as it involves 3D Touch. In the video, Rodriguez initiates a Twitter search via the “Hey Siri” feature, without unlocking the phone. His search of a contact brought up contact information, allowing him to press down on it with 3D Touch to bring up a Quick Actions menu.

The Daily Dot found that you can ask Siri to search Twitter for “@gmail.com” or any other second half of an email address to pull up a contact’s informatiom. When you see a tweet with an email address, that’s when you can bring up the Quick Actions menu.

Rodriguez then taps “Add to Existing Contact,” which brings up his entire Contacts list, and he follows that by tapping on a contact and hitting “Add Photo,” which then offers full access to his photo library.

Essentially, Rodriguez shows the flaw could offer someone else using a locked device access to Twitter contact information, your contacts, and your photos. Do note that it’s only possible to access if you have granted Siri access to Contacts, Photos, or Twitter account information.

It also seemed to vary as to whether you can access this Twitter search without providing a passcode — most of the time Siri asked for a passcode, but some times it randomly went ahead with the search.

An Apple spokesperson says the issue was fixed this morning, and the fix is rolling out server side globally.

If you’re still wary, you can turn off Siri’s access to search Twitter by heading to Settings, finding Twitter, and toggling Siri off.

Julian Chokkattu
Former Digital Trends Contributor
Julian is the mobile and wearables editor at Digital Trends, covering smartphones, fitness trackers, smartwatches, and more…
Apple just admitted defeat to Android phones
A Google Pixel 8 Pro in Porcelain (left) with an iPhone 15 Pro in Blue Titanium held in hand.

For years, Apple’s smartphones have held a decisive upper hand over Android devices in one crucial aspect: the longevity of the software support cycle. In a nutshell, as long as your phone keeps getting updates, it will run just about fine.

Brand assurances play a crucial role in buyer behavior, as long-term update support means your phone will not only get new tricks but also security flaws patched. Notably, Apple is not into the habit of quoting how many years it will offer software support for each device, but it has held the crown for a while.

Read more
Google is making it easier to ditch your iPhone for an Android phone
Samsung Galaxy S24 Ultra and iPhone 15 Pro in hand.

Switching phones is never a smooth process, even if you’re switching between two different Android phones. However, when you’re trying to switch from an iPhone to Android or vice versa, it can be extra complicated -- and you can lose data and apps that you rely on. This is especially the case with Apple-to-Android transfers because the iPhone has a much stronger ecosystem lock-in with things like iMessage, iCloud backups, and exclusive apps like Overcast and Hyperlapse.

The good news is that with its Data Transfer Tool (also called Pixel Migrate on Pixel devices), Google may be trying to mitigate some of the phone-switching problems that arise -- specifically, losing access to your Live Photos. According to an APK teardown from Android Authority, Google’s Data Transfer Tool will finally resolve the problem of migrating iOS Live Photos to Android. It will do this by converting them over as Motion Photos.

Read more
The iPhone’s new AI features may come with a gigantic catch
An iPhone 15 Pro Max laying face-down outside, showing the Natural Titanium color.

Imagine paying a minimum of $999 for a new iPhone 14 Pro in 2022, only to discover that it can’t run the full iOS 18 experience in less than two years. It might sound dystopian, especially for a product known for its long shelf life that's largely the result of an industry-leading software update policy at Apple.

Yet, it seems that nightmarish surprise will be here in just over a week. Bloomberg recently reported on some crucial AI-driven features coming to iOS 18, with Siri being one of the main recipients of all that innovation. But iPhone users might have to pay a pretty price for it all.

Read more