Apple

October 26, 2010
 

Passcode Hack raises Security Concerns for iPhone Users

Today, a MacRumors forum member shared an interesting iOS security flaw. This flaw basically allows users to make phone calls using Passcode Hack method on their iPhone devices.

Some forum members have reported the Passcode Hack issue to Apple, and we can expect a quick firmware update soon. Apple has planned to provide iOS 4.2 in November, but it seems that they will have to roll out iOS 4.1.1 update as soon as possible.

Here’s what the guy has said -

I think I just found a security flaw in ios 4.1.
When you iPhone is locked with a passcode tap Emergency Call, then enter a non-emergency number such as ###. Next tap the call button and immediately hit the lock button. It should open up the Phone app where you can see all your contacts, call any number, etc.
My iPhone is jailbroken so that could be causing it. Can anyone confirm that it works on non-jailbroken iPhones?

What does Passcode Hack mean?

It’s an old method to access some of the features/apps of iDevices. In 2008, we have seen similar Passcode Hack for iPhone devices. However, Apple team patched it with firmware update. The recent Passcode Hack uses the security hole in the firmware and allows users to make calls. Some users have also claimed that it can be used to access photos and e-mails on the iPhone.

If you’re still confused, watch the following video to know more about it.

You can try these steps to understand the Passcode Hack -

  1. Use an iPhone device with Passcode Lock and press the ‘Power’ button to lock the screen.
  2. Once again press the ‘Power’ button to unlock the screen. Now tap ‘Emergency Call’.
  3. Enter any non-emergency number such as ###.
  4. Now, tap the ‘Call’ button and quickly press the ‘Power’ button.
  5. Phone app will pop up on your screen.

The above method has worked on jailbroken as well as non-jailbroken iPhones.

iPhone jailbreakers and unlockers should save their iOS 4.1 SHSH blobs as Apple will patch other holes too. Chpwn’s tweet on Twitter -

passcode hack