Apple Fixes iPhone Siri Bug That Allowed Anyone Access to Contacts, Photos

Advertisement
By Hayley Tsukayama, The Washington Post | Updated: 6 April 2016 10:32 IST
An online video of a newly discovered bug in Apple's iOS 9.3.1 operating system is making the rounds, showing that it has been possible to access an iPhone user's contacts and photos without entering a passcode or scanning a fingerprint.

It does require a very particular set of circumstances. For one, you have to allow Siri to access your Twitter account, which requires your passcode or fingerprint. You also have to have a phone that uses Apple's pressure-sensitive Force Touch, namely an iPhone 6s or iPhone 6s Plus.

Finally, at least according to the video, you have to find a tweet that contains an email address (or something formatted like an email address) in order to use 3D Touch and call up the phone's contacts menu.

If all those requirements are met, you simply have to push down on the part of the message containing the address and call up a menu to add a new contact or edit an existing contact. Doing so takes you to the phone's address book. If you opt to edit a photo in an existing contact or add one to a new contact, you can also choose to use a photo from the phone's photo album - all without a passcode.

Advertisement

While it's perhaps unlikely that someone would come across this bug accidentally, it could be easy to trigger if you're looking for it. Someone could tweet an email address from their account for this purpose or, as I did to duplicate this bug, could simply do a search for something like "outlook.com" or "gmail.com" to find a message that then allows access to the contacts menu.

Advertisement

Disabling Siri's access to Twitter did not appear to fix the problem; disabling Siri, of course, would.

An Apple spokeswoman said the problem had been fixed Friday morning. Most consumers should have a fix in place, without the need for a software update, she said.

Advertisement

Still, the YouTube channel that posted the video showing the bug has several other clips pointing out ways to get into certain parts of the iPhone without having to enter a code or fingerprint on Apple's lock screen. Many of these techniques involve Siri - though some of these too have since been fixed.

The Twitter account associated with the YouTube channel belongs to a user going by the name of Jose Rodriguez. The user has called for Apple to launch a "bug bounty" program that would pay well-intentioned hackers to find problems like this and bring them to the company's attention.

Advertisement

© 2016 The Washington Post

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apple, Encryption, Mobiles, Siri, iPhone
Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  4. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  5. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  6. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  7. Nothing Phone 3a Lite Goes on Sale in India at This Price
  8. Realme Says It Will Launch Two New Narzo Smartphones in India Soon
  9. Instamart to Provide 10-Minute Delivery of Samsung Galaxy Devices
  10. Samsung May Launch Official 25W Magnetic Qi2 Charger With Galaxy S26 Series
  1. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  2. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  3. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  4. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  5. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  6. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  7. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  8. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
  9. Realme Narzo Phones Confirmed to Launch in India Soon via Amazon
  10. Samsung Galaxy Watch Ultra 2 Launch Timeline Leaked; Could Debut Alongside Samsung Galaxy Watch 9
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.