Security flaw allows calls (and more) from a locked iPhone running iOS 4.1

Security

Blog 9to5Mac has picked up on an interesting bug in iOS 4.1, running on the iPhone, that will allow users to bypass the device’s lock screen and make phone calls. From a locked iPhone pressing the “Emergency Call” button, dialing a non-emergency number (such as “###”), then quickly pressing “Send” followed by the iPhone’s lock key will actually force the device into the “Phone” application. From there you can access favorites, contacts, the dial pad, recent calls, and voicemails. The “home” button remains inactive throughout the process, preventing users from jumping to the home screen, however… going to the “contacts” tab, selecting a contact, and clicking “Email” or “Share contact” will allow a bypasser to send emails and MMS messages.

The issue is reminiscent of a bug in Motorola’s BLUR interface that allows users to make calls using voice actions from a locked screen we told you about last week. We’ve passed the information on to Apple and, hopefully, a fix is included in the next software update. We have a short video demonstrating the bug after the break.

Read

80 Comments
  • SoCaller

    Managed to figure it out on the first try. Sent emails, texts and searched my corporate global directory.

  • Apocalypse

    cause as the Scottish say ‘Apple is Craaaaaaaaap!”

  • Seabass

    WoW this is sooo Magical!!!!

  • Neo

    you can access favorites, contacts, the dial pad, recent calls, and voicemails. The “home” button remains inactive throughout the process, preventing users from jumping to the home screen.

    So? who cares, as long as they can’t use my Call of Duty app or my SF4 it doesn’t affect me none.

  • Spragga

    Apple fail. CTO’s take note.

  • AdamC

    Wow, poor man’s iPhone users just can’t wait to jump in whenever the iOS has a bug.

    Sorry guys VZ is giving away the poor man’s iPhones and yet it is not enough to better the paid iPhone.

  • doherty192

    Hey guys. Saw a great article about this at http://www.mailtimes.org

  • Joey g

    That’s great, can’t wait 2 fuk with people

  • http://emuneee.com Evan

    As bad as the bug may be, Apple will patch this quickly.

  • LoRD EPoX

    Verified on my 3GS running 4.1. Allows you to view contacts, make calls, and view voicemail… this one they need to address sooner than later. A pint on me for the guy who figured this bug out, pure genius!

  • jason

    and they want to get into corporate world? yeah stick with the gamers and fart apps users.

  • jimjon

    fuck all you iphone haters………..

    • Drew

      …aaaannnndd fuck you back.

  • Juan barreto

    Also on the iphone 3gs u can call someone by voicecontrol

  • Elektra

    For me, this is not a big deal. I have friends who use my iphone all the time to make calls, browse the interned, view/take photos, games, etc. So if you think about it, they don’t even have to figure out a way to break the passcode to get through my contacts list. Matter of fact, I just leave it unprotected at all times.

    What I do though is, I have apps, and there are tons of apps available, that have password protection wherein I can save photos and personal notes into that I wouldn’t want to share with just anyone. That way even if someone bypasses the passcode of my iphone, they still couldn’t be able to access personal data.

    • tim

      I like how you find a pro to this flaw in Apple programming. Typical Apple fanboi. Understand there are people who when they lock their phone they want it locked… thats the whole point of locking it. Apple screwed up, i’m sure it will be fixed ASAP but just admit.

      • Elektra

        I am not denying that there’s a bug. All I am saying is, it is not a major security threat like the article implies it to be. As I have said, a lot of times, friends borrow your iphone and use it anyway.

  • Perspective

    Wow. So first it was dropping calls, now it’s making calls even when locked.

    No wonder the iPhone 4 whipped RIM and Android’s ass last quarter. . .it’s the phone for everyone.

    • Elektra

      It’s because all those negative issues about the iphone are nothing more than exagerrated ones :-)

  • Diogo Serra

    If you change the time for lock screen from immediately to 1 min at least it doesn’t have that behavior.

  • Chir Patel

    This doesn’t happen on my Iphone, it is not jailbreak, and running ios 4.01 (8B117).

    Am I missing some thing here. This is what I did

    1) lock phone
    2) go to emergency dialpad
    3) ### and send
    4) press on/off button quickly.

  • Cc

    On a jailbroken iOS 4.1 3GS iPhone, if you change your password setting to a complex password (make sure “simple password” setting is OFF (Settings>General>Passcode Lock(On)>Simple Passcode(Off)), then give your iPhone a complex password, this bug is defeated.

  • amanda

    This also works on the iphone 4.0 update. You can bypass the lock screen, & go to the phone app, contacts, & send mail & such. Only thing is, it re-locks itself after a few seconds if you don’t press anything after bypassing.

  • http://Www.chrissyone.com ChrissyOne

    So… You can bypass the lock screen, as long as you know the lock key.

    Uh huh.

  • http://Www.chrissyone.com ChrissyOne

    Okay, sorry – the video made more sense than the article.

    • Jm

      I read it the same way; it was pretty poorly written. I’ve not heard that switch called the ‘lock key’ before.

  • DC

    This does not work on my iPhone 3G with 4.1.

  • http://securitycompanys.co.uk/about Security

    I have visited your weblog and I find this post very Interesting. I bookmarked it. Can anyone else send me other related topics I can read about? Thank you for shearing. Ray

  • Drew

    My God, this device has to have the most security flaws of any phone I’ve heard of… How ironic from such a “closed” operating system. Too bad you don’t have Adobe to blame for such poorly implemented coding.

  • Megangomez18

    Tried to do this several times.. Does not work!!

1 2
blog comments powered by Disqus