Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster
Apr 12, 2001
63,524
30,826



A Siri vulnerability that allowed access to a user's photos and contacts on a locked iPhone running iOS 9.3.1 was patched server-side this afternoon by Apple.

Shared last night by Jose Rodriguez, the vulnerability used Siri's ability to access Twitter to find an email link or phone number, which could be pressed to open up an editable list of contacts even on a device that was locked. Through access to contacts, a user's full photo library was also visible.

As seen in the video below, the vulnerability relied on asking Siri to perform a Twitter search. If an email address, phone number, or other contact related detail came up, it would give direct access to Photos and Contact data. While the method worked on the iPhone 6s as of this morning, it is now disabled on all devices because it is no longer possible for Siri to conduct a Twitter search on a locked device.


When using a locked iPhone, asking Siri to "Search Twitter" now results in the personal assistant saying "You'll need to unlock your iPhone first." Without the ability to search Twitter on a locked device, there is no way to get the exploit to work. Apple confirmed the fix in a short statement given to The Washington Post.

According to 9to5Mac, a second Siri-related bug was also fixed today. Previously it was possible to enable both Night Shift and Low Power Mode by asking Siri to enable Night Shift after Low Power Mode was turned on, but that is no longer possible. Siri now warns that turning on Night Shift requires turning off Low Power Mode.

In early iOS 9.3 betas, Night Shift did work with Low Power Mode, but in iOS 9.3 beta 4, Apple removed the functionality. Night Shift and Low Power Mode cannot be run simultaneously.

Article Link: Apple Fixes Siri Bug Allowing Access to Photos and Contacts on Locked Device
 

spherox

macrumors member
Jan 26, 2015
45
416
Hate Apple or not, but you have to give them props for these security updates. Personally, the fact that I only see this bypass on YouTube a few hours ago and have just seen an article about Apple sending out an update to fix it just amazes me. I remember when I had an LG and I had to beg and pray that I would even get an update, lol.
 

djcerla

macrumors 68020
Apr 23, 2015
2,310
11,991
Italy
Hate Apple or not, but you have to give them props for these security updates. Personally, the fact that I only see this bypass on YouTube a few hours ago and have just seen an article about Apple sending out an update to fix it just amazes me. I remember when I had an LG and I had to beg and pray that I would even get an update, lol.

Actually it was a server side fix, not a software update.
[doublepost=1459903747][/doublepost]
Siri is as attractive to me as FaceBook or Microsoft.

I would love an iPhone that didn't support it.

Options>General>Siri>disable

There you have it.
 

Benjamin Frost

Suspended
May 9, 2015
2,405
5,001
London, England
Wow. Delete your account.

Just today, I was typing away, when suddenly a bloody popup window asked me if I wanted to turn on dictation. Just bugger off, Apple. I don't want your foul news, I don't want your cynical music subscription, I don't want your spam forced down my throat.

I wish Donald Trump was CEO of Apple. He'd be a darn sight better than Cook.
 

cdm283813

macrumors 6502
Jan 10, 2015
489
280
Hate Apple or not, but you have to give them props for these security updates. Personally, the fact that I only see this bypass on YouTube a few hours ago and have just seen an article about Apple sending out an update to fix it just amazes me. I remember when I had an LG and I had to beg and pray that I would even get an update, lol.

That is the one thing I will miss. When you have issues with iPhone or iOS tons of people find out. I still have my 6S but the S7 is my daily driver until the iPhone 7 comes out. Then it's back to Apple. Hard liking 2 mobile operating systems.
 

Hastings101

macrumors 68020
Jun 22, 2010
2,339
1,460
K
Just today, I was typing away, when suddenly a bloody popup window asked me if I wanted to turn on dictation. Just bugger off, Apple. I don't want your foul news, I don't want your cynical music subscription, I don't want your spam forced down my throat.

I wish Donald Trump was CEO of Apple. He'd be a darn sight better than Cook.

Yeah, he could build a wall around Siri and then we'd never have to hear from her again!
 

chrfr

macrumors G5
Jul 11, 2009
13,520
7,043
Just today, I was typing away, when suddenly a bloody popup window asked me if I wanted to turn on dictation. Just bugger off, Apple. I don't want your foul news, I don't want your cynical music subscription, I don't want your spam forced down my throat.
Wow. This is triggered by pressing the "fn" key twice, quickly. I don't see how it could be considered "spam."
https://support.apple.com/HT202584
 

Soccertess

macrumors 65816
Oct 19, 2005
1,277
1,824
GUYS! We are all safe.. It's not like Siri actually understands that many people...

If it had the capability of google now, then there would be an issue!
 
  • Like
Reactions: BigHonkingDeal

Candlelight

macrumors 6502a
Oct 12, 2011
837
731
New Zealand
Okay you've baited me... Why?
Why not? The phone works, does everything I want it to. I have Siri turned off, 3D Touch set to minimum (pity no way to turn it off fully), don't need Night Shift or any of the other features 9.3 brings. 9.2 works, so why change it?
 

Tubamajuba

macrumors 68020
Jun 8, 2011
2,185
2,443
here
Just today, I was typing away, when suddenly a bloody popup window asked me if I wanted to turn on dictation. Just bugger off, Apple. I don't want your foul news, I don't want your cynical music subscription, I don't want your spam forced down my throat.

I wish Donald Trump was CEO of Apple. He'd be a darn sight better than Cook.
Instead of wishing for a very unlikely scenario, you could always take your business elsewhere. I'm sure you'd be much happier if you stopped using Apple products.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.