iOS 12.1 lockscreen security flaw can expose your contacts list, here's how to protect yourself

15comments
Video Thumbnail

Apple's software updates for the iPhone, iPad, and Apple Watch have been out for a couple of days, and so far, the rollout isn't exactly going smoothly. The company had to pull WatchOS 5.1 after receiving reports that the update bricked certain Apple Watch Series 4 units, and now, it appears that some issues have slipped into the latest version of iOS as well.

A lockscreen security flaw that is specific to iOS 12.1 has been discovered by Jose Rodriguez. On October 31, the YouTuber uploaded a video showing how lockscreen passwords on an iPhone can be bypassed in order to gain access to the owner's contact list via Siri. 

Asking the voice assistant to make a phonecall and then switching to FaceTime allows attackers to exploit the new group FaceTime feature into adding more people to the call. From there, the user's complete contact list is exposed, and malicious parties can even use 3D Touch in order to get more info on people on the list.

Keep in mind that this exploit requires the attacker to have physical access to your phone, so we recommend that you don't leave it unattended. Apple will most likely address the issue soon, but if you want an immediate fix, just disable the activation of Siri from your lock screen. This is done by going to Settings -> Siri & Search -> Access When Locked.

Unlimited plans for $15/mo at Mint!

$180
$360
$180 off (50%)
Mint Mobile is also offering an incredible bargain for those seeking unlimited data! The carrier's latest deal lets you grab any unlimited plan for just $15/mo, bringing the 12-month Unlimited plan to $180 instead of $360.
Buy at Mint Mobile
Google News Follow
Follow us on Google News
COMMENTS (15)

Latest Discussions

by RxCourier9534 • 7
by MagentaMarx • 10

Recommended For You

FCC OKs Cingular\'s purchase of AT&T Wireless