apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally
No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally
No Result
View All Result
apple patient
No Result
View All Result

iOS 14.8 & iOS 15: Vulnerability allows access to notes despite lock screen

by Milan
September 23, 2021
in News
iOS 14.8 & iOS 15 vulnerability

MYKOLAIV, UKRAINE - JULY 10, 2020: New modern Iphone 11 with numpad for entering passcode near box

Security researcher Jose Rodriguez has discovered a new vulnerability in iOS that allows attackers to bypass a secured iPhone lock screen and access notes.

The security flaw, which is present and works on iOS 14.8 and iOS 15, was recently discovered by Rodriguez on his YouTube channel To bypass the lock screen of the respective iPhone, Rodriguez first asks Siri to activate VoiceOver and navigates to Notes in the Control Center. As expected, a new note field appears without the user's content visible.

Attacker can export notes

By opening the Control Center again, Rodriguez selects the stopwatch and opens it. After some trickery, he can select the previously opened Notes app using VoiceOver. Instead of an empty note, iOS now grants access to the entire notes database including stored content, which in the example case includes a note with text, an audio recording, an HTML link, a contact card and more. Rodriguez then uses VoiceOver's rotor to select the note and copy it to a second iPhone for export. The target device is then called from a second iPhone. The attacker can now reject the call and paste the copied text into their own message reply. Alternatively, the text can also be pasted into messages when a second device sends an SMS or iMessage message to the target iPhone.

Password-protected notes remain unaffected by the vulnerability

Although the vulnerability is of course dangerous, an attacker cannot easily exploit it. A few other requirements must be met here. The attacker needs physical access to the iPhone. In addition, Siri must be activated, the control center must be available on the lock screen, and notes and stopwatch must be stored in the control center. The attacker must also know the phone number of the potential victim. So the vulnerability is dangerous, but exploitation can be easily prevented. It remains to be seen when Apple will fix the whole thing with a software update. (Photo by New Africa / Bigstockphoto)

  • iOS 15 improves Face ID anti-spoofing models
Have you already visited our Amazon Storefront? There you'll find a hand-picked selection of various products for your iPhone and other devices – enjoy browsing !
This post contains affiliate links .
Add Apfelpatient to your Google News Feed. 
Was this article helpful?
YesNo
Tags: iOSiOS 14.8iOS 15
Previous Post

Official: EU proposes USB-C standard for smartphones

Next Post

ID Wallet: Store German driving license on your iPhone

Next Post
ID Wallet App Store driver's license on iPhone

ID Wallet: Store German driving license on your iPhone

Apple Notes App iOS 26

iOS 26: These new features await you in Apple Notes

June 13, 2025
iPadOS 26 iPad Fold

iPadOS 26 is ready for the upcoming 18.8-inch iPad Fold

June 13, 2025
Apple Music iOS 26

Apple Music gets a DJ feeling with AutoMix feature

June 13, 2025

About APFELPATIENT

Welcome to your ultimate source for everything Apple - from the latest hardware like iPhone, iPad, Apple Watch, Mac, AirTags, HomePods, AirPods to the groundbreaking Apple Vision Pro and high-quality accessories. Dive deep into the world of Apple software with the latest updates and features for iOS, iPadOS, tvOS, watchOS, macOS and visionOS. In addition to comprehensive tips and tricks, we offer you the hottest rumors, the latest news and much more to keep you up to date. Selected gaming topics also find their place with us, always with a focus on how they enrich the Apple experience. Your interest in Apple and related technology is served here with plenty of expert knowledge and passion.

Legal

  • Imprint – About APFEPATIENT
  • Cookie Settings
  • Privacy Policy
  • Terms of Use

service

  • Partner Program
  • Netiquette – About APPLEPATIENT

RSS Feed

Follow Apfelpatient:
Facebook Instagram YouTube threads
Apfelpatient Logo

© 2025 Apfelpatient. All rights reserved. | Sitemap

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally

© 2025 Apfelpatient. All rights reserved. | Page Directory