Home / Vulnerability / Siri flaw in iOS7 allows anyone to send emails and post on Facebook

Siri flaw in iOS7 allows anyone to send emails and post on Facebook

Here is another flaw found by security researchers in the newly released iOS 7. Anyone with prior knowledge can leverage Siri flaw, allowing them to take control of the iPhone even when locked.
Siri is the intelligent personal assistant feature installed on iPhones.

So what exactly can a malicious minded person do in the device?

Related News : Lockscreen of iPhone’s iOS 7 can also be bypassed.

According to Cenzic researchers, Abhishek Rahirikar and Michael Yue, the flaw will allow :

  • make phone calls
  • send messages and emails using the device owner’s identity
  • view call history
  • view certain contacts
  • gain access to personal information
  • make posts on Twitter and Facebook
  • and retrieve addresses saved in Apple Maps.

The security researchers however said that it only can be applied if the attacker has direct access to the device. They then recommended to disable the feature ‘SIRI’ or try to not hand iPhone running iOS7 to people that can not be trusted.

Currently, Cenzic calls on Apple to take a look on these vulnerabilities and solve them as soon as possible. Proof of concept is embedded above.

About Clifford Trigo

Hi there! I am Clifford Trigo from the island of Bohol, come over here and lets have fun! :3 Just keep reading :D