Tuesday 5 April 2016

New iPhone 6s passcode bypass lets handlers access Photos and Contacts; here’s how to protect yourself

A new iPhone 6s/6s Plus passcode bypass flaw is making its rounds on the internet today, and it’s similar to flaws we’ve seen in the past on iOS. Don’t be overly alarmed, though, as the odds of this happening to you are slim. Besides, if you are concerned, there are some bonafide ways to go about protecting yourself.

The bypass only works on the iPhone 6s and iPhone 6s Plus, because those devices feature 3D Touch, which is used for this particular variant of the passcode bypass trick. The flaw is present in the latest iOS 9.3.1 update.

Here’s how to test the passcode bypass

Step 1: Lock your device.

Step 2: Invoke Siri and say “Search Twitter”.

Step 3: Once Siri asks what to search for, say: “at-sign yahoo dot com” or any other popular email domain. The goal is to find a tweet containing a valid email address.

Bypass passcode siri twitter

Step 4: Once the search results are returned, tap on a tweet with a valid email address.

Step 5: 3D Touch the email address to bring up the contextual menu.

Step 6: Tap Create New Contact → add photo in order to view the photos on device. You may be asked to give Siri access to the Photo Library. You can also view contacts on device by use the Add to Existing Contact option instead.

No comments:

Post a Comment