A new flaw on iOS 9 has emerged that lets anyone access photos, contacts on iPhone 6s and 6s Plus without unlocking it.
Soon after Apple fixed the problem of apps crashing on devices with iOS 9.3.1 update, a new flaw has emerged that lets anyone access photos, contacts on iPhone 6s and 6s Plus without unlocking it.
A YouTube users, who goes by the name videosdebarraquito, has posted a video showing how the flaw. The video shows how the Touch ID or pass code can be bypassed using Siri.
First up, one needs to activate Siri, which can be done by long pressing the home screen or saying Hey Siri. Next, ask Siri to search Twitter to which Siri will respond by asking what to search for. Mention ‘@gmail.com’ or simply the domain name of any email provider with ‘@’ prefix.
Read: Apple iOS 9.3: iPhone, iPad users complain of Safari crashing after update
Siri will then show a list of Tweets in the search results, from where one needs to select a tweet with full e-mail address. Now, one can take advantage of this loophole only on iPhone 6s and 6s Plus because of 3D Touch. So, one needs to long press the email address until the pop-up appears and from there on, users can click on ‘Add new contact’ to access photos on the device or ‘Add to existing contacts’ to view contacts on it.
The hack might sound easy, but, if we go by reports, it requires several attempts before Siri responds. According to DailyDot, “The exploit works with iOS 9 through the newly released 9.1.3.”
Also Read: Apple iOS 9.3 preview: Night Shift mode, security for Notes app and other features
Users wil have wait for Apple to fix the glitch. Meanwhile, the devices can be protected by disabling Siri access to photos by going to Privacy option in Settings, then Photos and disable Siri there. Also, users can disable Siri from the device till Apple comes up with a solution.