iOS 11 Bug Can Give Anyone Access to Your Photos

Advertisement
By Gadgets 360 Staff | Updated: 20 October 2017 17:41 IST
Highlights
  • There is a big flaw in iOS 11 that Apple hasn't patched yet
  • The flaw lets an attacker gain access to Photos folder on victim's iPhone
  • The vulnerability can only be exploited in a certain circumstance

A potential vulnerability found in the latest version of iOS mobile operating system can give anyone access to the Photos folder on your iPhone, according to a widely circulated video on YouTube.

The vulnerability, first reported by YouTube channel iDeviceHelp, affects iOS 11.0.3, the newest version of Apple's mobile operating system for general public, and iOS 11.1 beta, the preview version of the mobile operating system that Apple made available to developers this month.

According to iDeviceHelp, if an iPhone user has the target device in their possession and knows the device's phone number or Apple ID, then they could exploit what appears to be a bug in iOS to gain access to the photos saved on the victim's iPhone. We tried the exploit out on an iPhone 8 Plus running iOS 11.0.3, and were able to gain access to the Photos folder without entering a passcode, as claimed by the report.

Advertisement

So here is how it goes: the attacker gives the victim a FaceTime Audio call, but instead of accepting or rejecting the call, the attacker taps the "Message" button and selects the Custom option. Tapping on Custom option prompts the Message app to open, after which the attacker is required to randomly select three emoji characters.

Advertisement

Once done, the attacker hangs up the FaceTime call, and taps the Home button to trigger Siri and ask it to open Settings. At this point, Siri will ask the attacker to unlock the victim's iPhone. iDeviceHelp notes that the attacker now needs to press the power button to put the phone in sleep mode.

When this has been done, the attacker needs to make another FaceTime Audio call from their iOS device to the victim's handset. Once the victim's device gets the call notification, they need to tap the Message button again and then select "Custom" setting.

Advertisement

At this point, iDeviceHelp notes, that the attacker will find that they have complete access to Message app, and they can open the Photos folder and select and send any images from the victim's device.

Until Apple works on fixing the patch, a user could potentially try to disable Siri access from lock screen as a stop-gap solution to prevent anyone from accessing their device's data. As we mentioned, both the attacker and victim need to be using an Apple device, as the exploit requires the outgoing message to be an iMessage, and not a regular SMS.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Sale 2025: OnePlus 13s, OnePlus Nord 5 Deals Revealed
  2. Meta Connect 2025: Here's What to Expect from Tomorrow's Showcase
  3. Redmi 15R 5G With MediaTek Dimensity 6300 SoC, 6,000mAh Battery Launched
  4. Instamart Sale: iPhone 16, OnePlus 13R at Jaw-Dropping Prices
  5. Samsung Galaxy S26 Ultra Seen With New Camera Design in Leaked Case Renders
  6. Xiaomi 15T Specifications Leaked Ahead of Global Launch
  7. iPhone 16 Pro, iPhone 16 Pro Max Offers Listed Ahead of Flipkart Sale
  1. Ray-Ban Meta Gen 2 Smart Glasses Launched With 2X Battery Life, 3K Ultra HD Camera
  2. Meta Ray-Ban Display Smart Glasses Launched With AR Screen and Meta Neural Band
  3. Oakley Meta Vanguard Smart Glasses With a Centrally-Placed Camera Launched, Aimed at Athletes
  4. NASA’s Artemis Prepares Crews for Future Mars Missions
  5. JWST Identifies Compact, Metal-Poor Star-Forming Region Tracing Back to Early Universe
  6. Researchers Develop Method to Predict Rare Green Auroral Events on Mars
  7. Kanyakumari Now Streaming on This OTT Platform: Know Everything About This Telugu Romance Drama
  8. Demon Slayer: Infinity Castle OTT Release: Know When and Where to Watch it Online?
  9. Xbox Game Pass Wave 2 Titles for September Include RoadCraft, Frostpunk 2 and Hades
  10. Government Makes Cybersecurity Audits Mandatory for Crypto Exchanges Due to Rising Risks
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.