iPhone Security Hole Lets Anyone See Your Contacts
By doing weird things with Siri and VoiceOver mode, a dedicated attacker could get his or her hands on your iPhone contact list.
Here at Tom’s Guide our expert editors are committed to bringing you the best news, reviews and guides to help you stay informed and ahead of the curve!
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Daily (Mon-Sun)
Tom's Guide Daily
Sign up to get the latest updates on all of your favorite content! From cutting-edge tech news and the hottest streaming buzz to unbeatable deals on the best products and in-depth reviews, we’ve got you covered.
Weekly on Thursday
Tom's AI Guide
Be AI savvy with your weekly newsletter summing up all the biggest AI news you need to know. Plus, analysis from our AI editor and tips on how to use the latest AI tools!
Weekly on Friday
Tom's iGuide
Unlock the vast world of Apple news straight to your inbox. With coverage on everything from exciting product launches to essential software updates, this is your go-to source for the latest updates on all the best Apple content.
Weekly on Monday
Tom's Streaming Guide
Our weekly newsletter is expertly crafted to immerse you in the world of streaming. Stay updated on the latest releases and our top recommendations across your favorite streaming platforms.
Join the club
Get full access to premium articles, exclusive features and a growing list of member rewards.
iOS is renowned for having good security, but that doesn't mean the system is flawless. A novel, albeit not devastating, passcode bypass could let anyone with physical access to your iPhone see your entire contact list and their associated photos.
By taking advantage of a flaw in the way Siri, the contact list and the esoteric VoiceOver mode interact, a dedicated attacker could learn the names and contact information for every friend, coworker and loved one in your iPhone, plus whatever images you use to represent them.
The good news is that there's a very easy way to prevent anyone from taking advantage of this bypass: Don't lend your phone to anyone, unless you trust him or her implicitly. (And, obviously, don't let your phone get stolen.) The flaw takes a good minute or two to exploit and requires a user to have your phone in hand in a quiet environment.
MORE: iPhone XS Max and iPhone XS Review
The information comes from Spanish hacker Jose Rodriguez, who runs videosdebarraquito, an iPhone enthusiast channel on YouTube and Instagram. In a video entitled "Passcode Bypass iOS 12 (1-Call)," Rodriguez demonstrates how to access a user's contact list, even when the phone is locked down tight behind a passcode.
- Can a free iPhone VPN match up to a paid iPhone VPN?
Security news website Threatpost checked Rodriguez's work and discovered that the flaw works on iOS 12 and the iOS 12 beta on an iPhone XS. It's likely that this method can compromise all up-to-date iPhones, including the brand-new iPhone XS Max and XR as well as the XS. (Rodriguez himself uses an older Touch ID-enabled model in his demonstration video.)
But if you're curious how it works, Rodriguez discovered a rather clever exploit. Even when an iPhone is locked, a user can invoke Siri by tapping twice on the home button. Siri won't let you access sensitive information this way, but one thing you can do is ask Siri to turn on the phone's VoiceOver mode.
Get instant access to breaking news, the hottest reviews, great deals and helpful tips.
VoiceOver helps vision-impaired users by announcing whatever's currently highlighted on the screen: "Text message notification," for example, if someone sends you a text and you have notifications enabled at the top of your screen.
Using VoiceOver mode, Rodriguez was able to answer to an incoming phone call by using Message. However, VoiceOver mode does something funny. If you choose to "personalize" your messaging options, you can scroll through a blank screen, where your contact names and numbers would normally be.
This doesn't present a risk in and of itself, but users can then scroll to the top of the screen and select the text field to write in a contact's name. This is where the bypass comes in: If you write a letter or a number, the iPhone will show you all contacts with that letter or number included in them. From there, it's a matter of selecting a contact, tapping "Add information to existing contact," and being able to access a user's entire contact list.
More: Secure your phone with the very best mobile VPN apps
None of this is simple. To pull this off, you'd first need to tape over or disable the Face ID camera on an iPhone X, XS, XR or XS Max, or just use a Touch ID iPhone. You'd also need another phone to call or FaceTime the targeted iPhone at exactly the right moment in your passcode-bypass process.
And what a long process it is: The GadgetHacks website enumerated 37 separate steps in Rodriguez's hack, although GadgetHacks confirmed that it does indeed work.
IN any case, a successful bypasser would have access to every name, phone number and email address in your contact list. In all likelihood, this includes professional contacts, close friends and loved ones, all of whom could make easy scam targets.
What's also troubling is that if you have a photo attached to a contact, the attacker will be able to see that too. This isn't as damning as being able to access your entire photo library, but the attacker will know what many of your friends and family look like. If you have a lewd photo saved for a contact, of course, an attacker can see that as well.
It's worth pointing out that while this security hole is troubling, it's hardly catastrophic. There is no evidence that anyone could use this method to gain full access to your phone, nor is there any indication that anyone's tried to exploit it in the wild.
Tom's Guide has reached to Apple for comment. Whether or not we get a reply, the flaw will probably be addressed soon. Until then, keep your phone where you can see it.

Marshall Honorof was a senior editor for Tom's Guide, overseeing the site's coverage of gaming hardware and software. He comes from a science writing background, having studied paleomammalogy, biological anthropology, and the history of science and technology. After hours, you can find him practicing taekwondo or doing deep dives on classic sci-fi.
