Siri-ptitious Hacker Claims to Crack iPhone Lockscreen

Siri needs to brush up on her security. Using voice commands, one hacker claims it's possible to bypass the lock screen of an iOS device running version 7.1.1, access that phone's contacts list, and call a contact from the bypassed phone.

The hack has its limitations. The hacker needs physical access to the phone, which needs to be running iOS 7.1.1 and have Siri enabled on the lock screen. Further, the hack only gives the hacker access to the phone's contact list. Still, it's easy to imagine how this bypass could be used to cause some Siri-ous trouble.

MORE: 10 Tips Every iPhone Owner Should Know

Egyptian neurosurgeon and part-time hacker Sherif Hashim discovered the trick, which he demonstrated in a YouTube video posted May 4. In the video, Hashim first tries and fails to unlock an iPhone using its TouchID fingerprint scanner, showing that the phone is locked. He then activates Siri and tries to access the phone's contact list by saying "Contacts."

"You'll need to unlock your iPhone first," Siri says.  But then Hashim taps "cancel," activates Siri again, and says "Call." Siri then asks "With whom would you like to speak?" which allows Hashim to type names into a search bar for the phone's contact list. From there he can scan the phone's entire contact list, and call anyone from that list.

When we tried the same hack ourselves, we were unable to access our iPhone 5s' full contact list. However, we could call contacts by guessing certain names, such as Michael.

However, we then found that if the phone has more than one contact with the same first name (or even more than one contact whose names begin with the same two letters, such as "Mi"), a snoop can access the full contact list by searching for that name. If you do so, the phone will then display everyone in the contact list with that first name, and also present a "more" option. Tapping that "more" option will bring you to the entire contact list.

That the phone in question needs to have more than one contact with the same name, and that the attacker needs to know that name, might make this bypass seem difficult to do. But considering it's likely most people know more than one person with a common name like "Michael" or "Emily," it's probable that most iOS 7 devices who have Siri enabled on their lockscreens are susceptible to this partial bypass.

Ultimately, it's up to users to decide whether they want Siri to be accessible via the lockscreen. All you need to do is toggle the Siri button under "Allow Access When Locked" in the Touch ID & Passcode settings screen in iOS 7.

Email jscharr@techmedianetwork.com or follow her @JillScharr and Google+.  Follow us@TomsGuide, on Facebook and on Google+.

TOPICS

Jill Scharr is a creative writer and narrative designer in the videogame industry. She's currently Project Lead Writer at the games studio Harebrained Schemes, and has also worked at Bungie. Prior to that she worked as a Staff Writer for Tom's Guide, covering video games, online security, 3D printing and tech innovation among many subjects. 

Latest in iPhones
iPhone 17 Air render
iPhone 17 Air — new survey could be bad news for Apple's super thin iPhone
Render of the alleged design of the iPhone 17 Pro
New iPhone 17 Pro dummy leak highlights redesigned camera and part glass body
Siri in iOS 18 on iPhone
Users complain that Siri can’t answer even the most basic questions — here’s what we know
iPhone 16 next to samsung galaxy watch 7 and bose wireless earbuds on a composite image
Apple's walled garden is crumbling — EU orders iOS to open up to third-party devices
Apple iPhone 16 & 16 Plus hands-on.
Forget USB-C — a truly portless iPhone just got the all-clear from the EU
iPhone Flip render
iPhone Flip could solve one of the biggest problems with foldable phones — here's how
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Saturday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones