Apple plans to launch the final version of the iOS 13 operating system next Thursday, and of course with the new operating system, many great expected features will come, but unfortunately the next system will contain something unwanted. It houses a security hole in the lock screen.

IOS 13 will include a vulnerability in the lock screen

Security researcher Jose Rodriguez discovered a method that would bypass the screen lock on the iPhone running iOS 13 and then be able to access all the contacts stored in the device.

According to The Verge, “Jose” reported Apple in mid-July about a bug in the beta version of iOS 13, which allows unlocking the iPhone's screen lock. However, he noticed that this vulnerability is still effective on the GM version of the new operating system.

iOS 13

The seriousness of a loophole in the GM version, which is the acronym for Golden Master, is that this version is the last beta update of the system and is the same as the final version that Apple launches for the average user. Rather, it is the same version that factories download on the devices before packaging and shipping.

Do you know what this means! The iPhone 11 and 11 Pro are now being loaded with iOS 13 GM on them in factories, packaging and shipping to customers. That is, you will receive a device with a vulnerability to lock the screen. But of course, we cannot confirm this information with the presence of the vulnerability on 11 until after the phone is released.


How the vulnerability works

In order to hack and bypass the iPhone's screen lock, the person needs to make a video call via FaceTime and use the Siri voice assistant to activate the VoiceOver screen reader feature, after which the contacts on the iPhone can be accessed and then get e-mail, phone numbers, addresses, and all this without the need to open a screen The device (you can see how the vulnerability was implemented in the video below).

Although the implementation of this attack is a bit difficult, because the hacker needs physical access to the victim's iPhone for a few minutes in order to start a FaceTime call and enable the voiceover feature. Fortunately, this vulnerability does not allow the attacker to access other sensitive files such as photos and videos.


A series of iPhone system vulnerabilities

iOS 13

Finally, this is not the first time that vulnerabilities and threats have been discovered in the iOS operating system, as previous versions of the iPhone system have been exposed to similar vulnerabilities, such as in 2013 with the iOS 6.1 operating system, where hackers exploited a vulnerability in the system that allowed them to access phone records, contact information and even image files, and the same thing was repeated With iOS 7 and then in iOS 8.1, he found a loophole that allows bypassing the lock screen, and Jose Rodriguez discovered a similar bump last year on iOS 12.1, and now he finds the same vulnerability with the latest version of the iPhone operating system.

The security researcher explained that for some reason, Apple did not close it with iOS 13, but the beta versions of iOS 13.1 that are now with the developers have closed the vulnerability with it. It is rumored that Apple will launch update 13.1 in less than two weeks after the release of iOS 13.0, specifically on September 30, according to the rumors.

What do you think about this vulnerability and do you see it dangerous? Will finding a lock screen vulnerability affect your trust in iOS and Apple?

Source:

The Verge

Related articles