Amateur Hacker Jose Rodriguez on Friday unearthed another obscure, yet effective, lock screen bypass that leans on an unpatched bug in VoiceOver to gain unauthorized access to photos on a target device.
In a video posted to Rodriguez’s YouTube channel, the exploit requires a would-be hacker have both their personal device and a target iPhone handy at the time of attack.
The target iPhone first receives a phone call from an outside number, which triggers a standard iOS call dialogue. If the attacker does not know the target iPhone’s number, they can acquire caller ID information by invoking Siri and asking the assistant to call their personal phone digit-by-digit.