Skip to main content

A critical bug in Apple iOS allows Facetime users to access recipients’ microphone and front camera


 
  • A bug in Apple iOS allows Facetime users to listen and watch the call recipients before the call is even picked up.
  • Researchers confirmed that this bug exists in iOS 12.1.2 version.
Researchers uncovered a critical bug in Apple iOS devices that could allow Facetime users to access the microphone and front camera of who they are calling even if the call recipient does not answer the call.
How can the bug be exploited?
  • To use this bug an iOS user should call a person via Facetime and should add themselves as an additional contact to Group Facetime before the recipient answers the call.
  • By doing so, the microphone of the call recipient will be turned on and the caller can listen to what's happening in the room.
  • Furthermore, if the recipient presses the power button to mute the Facetime call, the front camera will be enabled.
This means that the Facetime caller could listen and watch the recipient without their knowledge.
The bug exists in iOS 12.1.2
BleepingComputer tested this bug and confirmed that this bug exists in iOS 12.1.2 version. However, when the researchers tested this bug against Apple Watch, they were not able to get the microphone working.
A Google Project Zero security researcher Natalie Silvanovich explained the theory behind this bug in a tweet, “Theory: FaceTime stores call participants in a list that doesn't allow duplicates, and uses the indexes for signaling. When the caller is added a second time, the entry at index 1 is set to answer, with the expectation that it is the caller.”
Researchers’ recommendations
  • Researchers suggest iOS users disable Facetime until Apple releases a fix to the issue as this bug could allow people to take compromising videos and audio without your knowledge.
  • Once Facetime is disabled, Facetime users will not be able to abuse this bug to listen and watch users without permission.
However, Apple stated that they were aware of this issue and are working on the fix which will be released in a security update later this week.

Global Locations

  • Block A, A-25, Second Floor, Sector 3
    Noida, Uttar Pradesh
    +91-120 429 1672+91 931 991 8771

Comments

Popular posts from this blog

Digital Marketing Services in noida

Red Securium Company Provide Digital Marketing Service In Noida Strengthen your brand positioning, awareness, revenue objectives and market share with our custom-built digital marketing services to suit their business needs. Get easily accessible to your target audience on mobiles and social networking sites across different platforms. Our cross-functional digital marketing experts offer end-to-end digital marketing solutions that are in step with your business's goals and policies. Our targeted digital marketing campaigns are custom-structured for helping you in strengthening your brand positioning, awareness, revenue objectives and market share. Digital Marketing Services  Digital Marketing Service  Social Network Marketing Service Seo Services Marketing  PPC Marketing Service  Social Media Marketing Sales Generation Services  Mobile Marketing Service  Content Marketing Service Event Marketing Service  Vide...

How To Access Notorious Dark Web Anonymously (10 Step Guide)

Are you trying to find out  how to access the dark web  and what is it? Well, look no further, we have gone and done the research so we could show you step by step the best and safest way how to access the dark net. We cover everything, from setting up Tor, how to choose a VPN , what not to do, finding the best sites to access, and extra steps to remain anonymous. It is extremely easy to access the dark web and even easier to be detected on it if you don’t take precautions. If you are new to the darknet, this guide will help you on your way. According to researchers, only 4% of the internet is visible to the general public. Meaning that the remaining 96% of the internet is made up of “The Deep Web”. Dark Web or Dark Net  is a subset of the  Deep Web  where there are sites that sell drugs, hacking software, counterfeit money and more. We explain this further down the article if you are not up to speed. If you are looking to access hidden marketpl...

Private data of almost 14,200 patients diagnosed with HIV leaked online

  The affected individuals included 14,200 individuals who had been diagnosed with HIV, of which 5,400 individuals were Singaporeans and 8,800 were foreigners. The leaked information included names, identification numbers, phone numbers, addresses, HIV test results, and other related medical information. Private data of almost 14,200 individuals who had been diagnosed with HIV up to January 2013 were leaked online. A US citizen residing in Singapore gained unauthorized access to the HIV registry and leaked the data online . Out of the 14,200 affected individuals, 5400 individuals were Singaporeans and 8,800 were foreigners. The leaked information included names, identification numbers, phone numbers, addresses, HIV test results, and other related medical information. US citizen gained illegal access to the HIV registry On 28, January 2019, Singapore's Ministry of Health confirmed in a  statement , that Mikhy K Farrera Brochez, a US citizen residing in Singapo...