Siri Suggestions Feature Can Be Misused for Phishing Scams: Report

Advertisement
By Tasneem Akolawala | Updated: 11 June 2018 18:44 IST
Highlights
  • Wandera demoed two ways in which phishers could misuse the feature
  • One way includes getting a reply to a fake email
  • Apple doesn't view it as security vulnerability

Photo Credit: Fortune

Apple's Siri contact suggestions to identify unknown calls and messages has been a helpful feature, giving us a probable idea of who the user may be, just in case we don't have the number saved on the phone. However, in a new development, cybersecurity company Wandera has now demoed how this Siri feature can be easily exploited and used for phishing attempts in the future. When a number is unknown, Siri attempts to find suggestions by throwing a 'Maybe: XXXX' banner on your incoming call screen or in iMessages as well. Phishers may try to use this Siri's 'Maybe' feature to mislead users of who they really are.

Fortune explains that this trick works in two ways - one way is to just make a fake account of the name you want to display in the Siri feature, and send an email to the target. If the target responds, then the 'Maybe' feature will show the fake account name every time the phisher calls or texts in the future.

"There are two ways to pull off this social engineering trick... The first involves an attacker sending someone a spoofed email from a fake or impersonated account, like "Acme Financial." This note must include a phone number; say, in the signature of the email. If the target responds-even with an automatic, out-of-office reply-then that contact should appear as "Maybe: Acme Financial" whenever the fraudster texts or calls next," the report notes. The second way is via text messaging. "The subterfuge is even simpler via text messaging. If an unknown entity identifies itself as Some Proper Noun in an iMessage, then the iPhone's suggested contacts feature should show the entity as Maybe: [Whoever]," the report explains.

Advertisement

Bloomberg's Mark Gurman notes that this Siiri contact suggestions feature has been around since iOS 9, and for all the users who don't wish to be misled, Apple could easily add a switch to toggle the Siri feature off. Wandera said it reported this issue to Apple which noted it as a software issue, and not a security vulnerability.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Siri, Apple
Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  2. Xiaomi 15T Arrives on Geekbench With 12GB of RAM and This MediaTek SoC
  3. OnePlus 15 Will Reportedly Arrive With an In-House Camera Engine
  4. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  5. Hidden Reason Behind Portugal's Deadly Earthquakes Finally Explained
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.