iOS 15: a flaw allows you to access the notes of an iPhone without unlocking it
iOS 15 seems to suffer from a big security problem, since it is possible to access the notes of a locked iPhone without unlocking it. A security researcher demonstrated the entire process on video.
Due to a security breach with VoiceOver, anyone can now access notes stored on your iPhone without unlocking it. After a series of manipulations, a malicious person could therefore copy the data and send them very easily to an accomplice.
In a tweet published last week, researcher Jose Rodriguez previously explained that the vulnerability was present in iOS 14.8 and in the pre-release candidate version of iOS 15. Since then, he has also confirmed that the public version of iOS 15, which arrived yesterday, suffers from the same problem.
How to access iPhone notes without unlocking it?
To bypass the lock screen of a target iPhone, Rodriguez first asks Siri to activate VoiceOver and navigate to the Notes button in the Control Center. As expected, a new Notes page appears with no user content revealed.
After opening the Control Center again, this time it opens the stopwatch, and after a few manipulations, the security researcher manages to select the Notes application previously opened via VoiceOver. He then manages to make the iPhone read all the content on the Notes application.
Thanks to VoiceOver controls, Rodriguez is also able to select all the content of a note, copy it, and message it to an accomplice who calls or sends a message to the target iPhone. As Rodriguez demonstrated, it is therefore relatively easy to access confidential information stored on an iPhone in the Notes application.
Now that the flaw has been exposed, on imagine that Apple will rush to fix it and offer a security update for all users. The recent iOS 14.8 update already fixed a serious security vulnerability, which allowed malicious web content to arbitrarily execute code on a user’s device. In the meantime, you can find all the next features planned by Apple which are not yet available on iOS 15.