iPhone XS Passcode Bypass Hack Exposes Contacts, Photos (threatpost.com) 23
secwatcher shares a report from Threatpost: A passcode bypass vulnerability in Apple's new iOS version 12 could allow an attacker to access photos and contacts (including phone numbers and emails) on a locked iPhone. The hack allows someone with physical access to a vulnerable iPhone to sidestep the passcode authorization screen on iPhones running Apple's latest iOS 12 beta and iOS 12 operating systems. Threatpost was tipped off to the bypass by Jose Rodriguez, who describes himself as an Apple enthusiast and "office clerk" based in Spain who has also found previous iPhone hacks.
Rodriguez posted a video of the bypass on his YouTube channel under the YouTube account Videosdebarraquito, where he walks viewers through a complicated 37-step bypass process in Spanish. Threatpost has independently confirmed that the bypass works on a number of different iPhone models including Apple's newest model iPhone XS. The process involves tricking Siri and Apple's accessibility feature in iOS called VoiceOver to sidestep the device's passcode. The attack works provided the attacker has physical access to a device that has Siri enabled and Face ID either turned off or physically covered (by tape, for instance).
Rodriguez posted a video of the bypass on his YouTube channel under the YouTube account Videosdebarraquito, where he walks viewers through a complicated 37-step bypass process in Spanish. Threatpost has independently confirmed that the bypass works on a number of different iPhone models including Apple's newest model iPhone XS. The process involves tricking Siri and Apple's accessibility feature in iOS called VoiceOver to sidestep the device's passcode. The attack works provided the attacker has physical access to a device that has Siri enabled and Face ID either turned off or physically covered (by tape, for instance).
Re: (Score:2)
well (Score:2)
Phil left this out of his iPhone presentation (Score:4, Funny)
Hacking Siri (Score:4, Insightful)
Seems even Siri is vulnerable to social engineering hacks. /s
Re:Hacking Siri (Score:4, Funny)
Luckily, as with all women, I turned off Siri when I first met her.
Re: (Score:2)
But Siri turns a lof of guys like Raj and me: https://www.youtube.com/watch?... [youtube.com] ;)
misleading a bit (Score:2)
Not as simple as it seems. (Score:2)
"...Use another iPhone and phone call or FaceTime call the target iPhone..."
I don't think there's a way to identify what the phone number of a random iPhone is without unlocking it first, is there?
Re: (Score:2)
Re: (Score:2)
Missed naming opportunity (Score:3, Funny)
Re: (Score:1)
XS? (Score:1)