Passcode Bypass Bugs Trouble iOS 9.1 and Later
Apple has yet to patch a series of bypass vulnerabilities in iOS that could enable an attacker to sidestep the passcode authorization screen on iPhones and iPads running iOS 9.0, 9.1, and the most recent build of the mobile operating system, 9.2.1.
Like all passcode bypass bugs, an attacker would have to have the device in their possession to carry out the attack, but that’s not a valid excuse for not fixing the vulnerabilities, researchers say.
The bugs can be used to access apps native to iOS, such as Clock, Event Calendar, and Siri’s User Interface, and that’s been the case for at least three months, according to Benjamin Kunz Mejri, a researcher at Vulnerability Lab, who divulged details on them Monday.
“The issue is not fixed after a three-month duration. We have the newest versions of iPad and iPhone and are still able to reproduce it after the updates with default configuration,” Mejri told Threatpost Monday.
For all of the work that’s been done to prevent the intrusiveness of Siri, the culprit behind several previous passcode bugs, each of the vulnerabilities can actually be triggered via the company’s voice-activated personal assistant, Siri.
Mejri broke down several attack vectors in a write up of the bugs the company’s site Monday morning, all which rely on an internal browser link request to skip the passcode screen.
In one, an attacker could request Siri to open an app that doesn’t exist. In turn Siri opens a restricted browser window to the App Store, and from there the attacker apparently could switch back to the home screen, either via the home button, or via Siri, without further authorization.
An attacker could also use Siri to open either the Clock or the Event Calendar app to exploit the bugs.
Another vector, the Clock app, gives users the option to buy alarm tones and when prompted, open a browser window, which lists some apps. At this point a user could navigate to another part of the phone, Mejri claims.
Both the Clock and the Event Calendar apps allow users to open links to the Weather Channel’s app, which if the user hadn’t installed it, would in the App Store. From there an attacker could simply jump back to the home screen as well, Mejri writes.
According to Vulnerability Lab, who disclosed the issue to the Apple’s Product Security Team shortly after the New Year, the company acknowledged the issue, but had no further conversation with the researchers, citing its internal security and company policy.
It’s unclear exactly when or if Apple, which did not immediately respond to a request for comment on Monday, will address the issue.
There’s a chance the company, deep in the throes of a much publicized battle with the F.B.I. surrounding encryption, could fix the bugs when it releases iOS 9.3 later this spring.
Unlike the phone the F.B.I. is trying to get into, the vulnerabilities Mejri dug up are only present in more recent devices like the iPhone 5, 5s, 6 and 6S, and the iPad Mini, 1 and 2.
Source | ThreatPost