Apple's new mobile operating system isn't as secure as the company claims. Apparently, iOS 12 came with bugs that allow a fairly complicated process to bypass the passcode.
Bypassing the password of course gives access to confidential data on the device, such as photos, the contact list, and the address book.
The process of exploiting the vulnerability is rather complicated and requires the use of Siri, VoiceOver, and the Notes app. The method works on iPhone smartphones running iOS 12. This includes models that support Face ID or Touch ID biometrics.
To bypass Face ID and Touch ID security mechanisms, you need to have physical access to the device (for a very short time), but also know the victim's phone number.
To bypass the passcode in iOS 12 you need to summon Siri from the lock screen and ask Apple's digital assistant to enable the VoiceOver service.
Then, you need to call the iPhone you want to unlock from another device and during the call, select the reply with message option and press the “+” button. If the VoiceOver service is enabled, sending the message from the victim’s smartphone will cause an error in the system, as a result of which the attacker can access confidential data on the device, such as photos, contact list and address book. Of course, he can see the list of your outgoing calls and get more detailed information about them by clicking on the “i” button.
The vulnerability was discovered by security expert Jose Rodriguez who published two videos to demonstrate the problem. The vulnerability has not yet been patched.
Watch the videos
