NEWS / SMARTPHONES

Yet another iPhone passcode security flaw allows access to internal storage

| by Nikhil Subramaniam | Smartphones

At this rate, Apple will have to update iOS every month. Close on the heels of the passcode bypass vulnerability found on iOS 6.1 earlier this month comes another passcode bypass vulnerability that lets attackers access users' photos, contacts and more by following a series of steps on an iPhone, iPad or iPod touch running iOS 6.1.

The vulnerability was revealed in a post on the Full Disclosure mailer last week by Benjamin Kunz Mejri, Founder and CEO of Vulnerability Lab. In the email, Mejri gives step-by-step instructions to reproduce the flaw. It is similar to the loophole around the passcode discovered earlier this month. The most ominous part of this bug is that it allows any hacker direct access (via USB) to your iDevice’s content stored on the internal storage without needing to enter a pin.

Top end model to be sold for Rs 59,500

Apple will reportedly fix the passcode bypass flaw in an upcoming update

 


All anyone has to do is dial an emergency number directly from the lockscreen. Immediately after dialing, you have to cancel the call and press the power button. Follow this by pressing the home button. Till here, the steps sound simple, but the next few require some dexterity. Depress the power button for 3 seconds and on the last of the three, press the power button while tapping the emergency call button. Next, remove the finger off the home button before releasing the power/unlock button. Here, Mejri says your screen (minus the top bar) will go black. In this state, connect the USB cable to your phone. This will allow you to access photos, contacts and whatever else you have stored in your iDevice’s internal storage without a pin from your computer.

The first half of the exploit is very similar to the earlier vulnerability. In fact, the Vulnerability Lab references this in its proof of concept. Apple released a 6.1.2 update last week that didn’t fix this security flaw. But the company is planning a 6.1.3 update, which it has started seeding to developers. iOS 6.1.3 will supposedly plug the passcode bypass trick. The forthcoming update will also reportedly kill the evasi0n untethered jailbreak.

 

Of course, it is not always possible to reproduce this flaw. iMore reports that if an attacker uses a computer that has not previously been connected to a particular iPhone or iPad, the passcode on that device cannot be bypassed. “With the device plugged in, once you enter your passcode, iTunes will never require you to enter it again. iTunes has some mechanism in place that will now allow your computer to talk to the device, even when the lock screen is present. Had the person in the video plugged their device in to a computer that it had never been plugged in to before, they would have met with an error message instead,” iMore’s report said.

Tags: iPhone 5 , iPhone , iPhone security flaw , iPhone 5 security flaw , iOS 6.1 security flaw , iOS 6.1 passcode bypass , iOS 6.1 security loophole , iOS 6.1 vulnerability , iOS 6.1 passcode problem , Apple iPad , Apple iPod , Apple iPhone 5 ,

iPhone 5 Box Prank - Randomness

25 Sep, 2012, 01:29 am IST

iPhone 5 Box Prank - Randomness

AUTO-CORRECT RANT

28 Feb, 2013, 03:13 am IST

AUTO-CORRECT RANT

Ellen is Ready for iPhone 5!

18 Sep, 2012, 06:31 pm IST

Ellen is Ready for iPhone 5!

 


SPOTLIGHT

Huawei Ascend Mate: A specifications review

Huawei Ascend Mate: A specifications review

Priced at Rs 24,900, the 6.1-inch Ascend Mate may face stiff competition...

By Anujeet Majumdar

Lenovo K900: A specifications review

Lenovo K900: A specifications review

Lenovo's new flagship, the K900, has a very attractive stainless...

By Nikhil Subramaniam

First impressions: Lenovo K900

First impressions: Lenovo K900

We got to spend some time with the new Lenovo flagship K900 and...

By Nikhil Subramaniam

MORE FEATURES

Lava Iris 504Q Review

Lava Iris 504Q Review

17 Jun, 2013, 09:42 AM IST

 7.0

Lava has just launched its newest smartphone in its ever-expanding Iris line-up—the Iris 504Q. Lava is targeting the mid-end segment with its price tag of Rs 13,499, and is looking to compete directly with the likes of Micromax’s Canvas line-up. Let’s see if it can compete, shall we?

Panasonic P51 Review

Micromax A88 Canvas Music Review

Gionee Elife E3 Review

WickedLeak Wammy Passion Z Review

Alcatel One Touch Idol Ultra Review

MORE REVIEWS