Apple Fixes Siri Bug Allowing Access to Photos and Contacts on Locked Device
A Siri vulnerability that allowed access to a user's photos and contacts on a locked iPhone running iOS 9.3.1 was patched server-side this afternoon by Apple.
Shared last night by Jose Rodriguez, the vulnerability used Siri's ability to access Twitter to find an email link or phone number, which could be pressed to open up an editable list of contacts even on a device that was locked. Through access to contacts, a user's full photo library was also visible.
As seen in the video below, the vulnerability relied on asking Siri to perform a Twitter search. If an email address, phone number, or other contact related detail came up, it would give direct access to Photos and Contact data. While the method worked on the iPhone 6s as of this morning, it is now disabled on all devices because it is no longer possible for Siri to conduct a Twitter search on a locked device.
When using a locked iPhone, asking Siri to "Search Twitter" now results in the personal assistant saying "You'll need to unlock your iPhone first." Without the ability to search Twitter on a locked device, there is no way to get the exploit to work. Apple confirmed the fix in a short statement given to
The Washington Post.
According to 9to5Mac, a second Siri-related bug was also fixed today. Previously it was possible to enable both Night Shift and Low Power Mode by asking Siri to enable Night Shift after Low Power Mode was turned on, but that is no longer possible. Siri now warns that turning on Night Shift requires turning off Low Power Mode.
In early iOS 9.3 betas, Night Shift did work with Low Power Mode, but in iOS 9.3 beta 4, Apple removed the functionality. Night Shift and Low Power Mode cannot be run simultaneously.
Popular Stories
Apple has announced it will be holding a special event on Tuesday, May 7 at 7 a.m. Pacific Time (10 a.m. Eastern Time), with a live stream to be available on Apple.com and on YouTube as usual. The event invitation has a tagline of "Let Loose" and shows an artistic render of an Apple Pencil, suggesting that iPads will be a focus of the event. Subscribe to the MacRumors YouTube channel for more ...
Apple has dropped the number of Vision Pro units that it plans to ship in 2024, going from an expected 700 to 800k units to just 400k to 450k units, according to Apple analyst Ming-Chi Kuo. Orders have been scaled back before the Vision Pro has launched in markets outside of the United States, which Kuo says is a sign that demand in the U.S. has "fallen sharply beyond expectations." As a...
Apple today released several open source large language models (LLMs) that are designed to run on-device rather than through cloud servers. Called OpenELM (Open-source Efficient Language Models), the LLMs are available on the Hugging Face Hub, a community for sharing AI code. As outlined in a white paper [PDF], there are eight total OpenELM models, four of which were pre-trained using the...
Apple is finally planning a Calculator app for the iPad, over 14 years after launching the device, according to a source familiar with the matter. iPadOS 18 will include a built-in Calculator app for all iPad models that are compatible with the software update, which is expected to be unveiled during the opening keynote of Apple's annual developers conference WWDC on June 10. AppleInsider...
The upcoming iOS 17.5 update for the iPhone includes only a few new user-facing features, but hidden code changes reveal some additional possibilities. Below, we have recapped everything new in the iOS 17.5 and iPadOS 17.5 beta so far. Web Distribution Starting with the second beta of iOS 17.5, eligible developers are able to distribute their iOS apps to iPhone users located in the EU...
Top Rated Comments
[doublepost=1459903747][/doublepost] Options>General>Siri>disable
There you have it.