Siri-ptitious Hacker Cracks iPhone Lockscreen

Siri-ptitious Hacker Cracks iPhone Lockscreen

Siri needs to brush up on her security. Using voice commands, it's possible to bypass the lock screen of an iOS device running version 7.1.1, access that phone's contacts list, and call a contact from the bypassed phone.

The hack has its limitations. The hacker needs physical access to the phone, which needs to be running iOS 7.1.1 and have Siri enabled on the lock screen. Further, the hack only gives the hacker access to the phone's contact list. Still, it's easy to imagine how this bypass could be used to cause some Siri-ous trouble.

MORE: 10 Tips Every iPhone Owner Should Know

Egyptian neurosurgeon and part-time hacker Sherif Hashim discovered the trick, which he demonstrated in a YouTube video posted May 4. In the video, Hashim first tries and fails to unlock an iPhone using its TouchID fingerprint scanner, showing that the phone is locked. He then activates Siri and tries to access the phone's contact list by saying "Contacts."

"You'll need to unlock your iPhone first," Siri says. But then Hashim taps "cancel," activates Siri again, and says "Call." Siri then asks "With whom would you like to speak?" which allows Hashim to search the phone's contact list. From there he can scan the phone's entire contact list, and call anyone from that list.

This hack doesn't give the hacker access to any of the phone's other features.

Apple has not yet responded to this particular bug in its iOS 7.1.1 lock screen, so it's unclear if and when a patch is coming. But considering 7.1.1 was just released two weeks ago, it might be some time before 7.1.2 rolls around. In the meantime, users can disable Siri on their lock screen to keep their devices safe from this hack.

Email jscharr@techmedianetwork.com or follow her @JillScharr and Google+. Follow us@TomsGuide, on Facebook and on Google+.

Copyright 2014 Toms Guides , a TechMediaNetwork company. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.