Skip to main content

Wed, 27 Aug 2008 Locked iPhones can be unlocked without a password

Simple flaw topples iPhone security and enables access to stored phone numbers.

Peter Sayer


  • Email to a friend
  • Print this article
  • Bookmark this page
  • RSS feed

Private information stored in Apple's iPhone and protected by a lock code can be accessed by anyone with just a few button presses.

The iPhone, like most mobile phones, can be locked with a four-digit code, but where other phones in their locked state only permit calls to emergency service numbers such as 911 (in the US), 999 (in the UK) and 112 (throughout Europe), a locked iPhone can be used to make a call to any number.

Question of the day!

Mark Hattersley
Editor in Chief

Do you share your creations online?

Question of the day!

Do you share your creations online?

% of Macworld readers agree with you

Yes
TBC
No
TBC

What do you create and how do you share it?

124 characters remaining

Follow the conversation at @TabletChat

paintings & illustrations, mostly, which i upload to flickr.RT @fragmentedm

I draw manga/anime characters. I also do graphic design and photography.RT @spialelo

Yes. I usually put them up on my #deviantart account for feedback on how to improve.RT @spialelo

However, that's not all you can do with a locked iPhone running the latest version of Apple's software, 2.0.2.

Pressing the emergency call button at the unlock screen, followed by two taps on the home button, takes you to the iPhone's private 'favorites' page without the need to enter the unlock code.

If the owner of the phone has favourite entries in their address book containing URLs, email addresses or mobile phone numbers, then those entries can be used to launch the browser, mail application or SMS (Short Message Service) software and gain access to private web favourites, email messages and text messages stored in the phone, again without entering the unlock code.

The security flaw, revealed by a member of the MacRumors.com forum, came as a surprise to an Apple spokeswoman in London, who said she would look into the matter.

One way to avoid such unauthorized access to email messages or web favourites would be not to add email addresses or URLs to favourite address book entries.

Apple pushed version 2.0 of its iPhone software as being more enterprise-friendly: some businesses had been reluctant to adopt the first version of the iPhone because it did not adequately protect corporate information stored in the device.

And meanwhile the mysterious application and iTunes folder content-eating bug on the iPhone also continues unexplained.

Email A Friend

Email this article to a friend or colleague:



PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

<<prev article | back to news index | next article>>

Comments received


Pete B said on Wed, 27 Aug 2008

iBloat. All hot air and no content.

Mark said on Wed, 27 Aug 2008

Misleading title:

It will not let you into the home screen so not totally unlocked.

Just change the option in the settings so that double tapping the home button to open the ipod functions, then all someone can do is play some of your music / videos

Matt said on Wed, 27 Aug 2008

If you set the home button double tap to "Home" it appears not to work. A work around for now at least.

Anon said on Thu, 28 Aug 2008

Another iFeature that will ensure no company security would allow it on a network.

Jason said on Fri, 29 Aug 2008

Yeah, because no company would allow unsecure devices onto their network, anything running Windows for example. Oh wait a moment....

anon said on Fri, 12 Sep 2008

2.1 is now out but... Try this:
enable your sim card and then lock you iphone.
Slide the locker. choose emergency call.
Dial any number you want and call...

Disclaimer
Opinions expressed here are those of the writers and do not reflect those of Macworld. Macworld accepts no responsibility legal or otherwise for their accuracy of content.
Click here to read the house rules.

Click here for the latest reader comments


Latest News


More news...