A flaw in iOS 13 can expose your contact details, and Apple’s known about the problem since July

Sep 19, 2019, 5:07 PM

AP Photo/Marcio Jose Sanchez, File...

AP Photo/Marcio Jose Sanchez, File

(CNN) — A flaw in iOS 13, the new iPhone operating system Apple released Thursday, exposes contact details stored in iPhones without requiring a passcode or biometric identification. And Apple has known about the flaw since July, a person who reported the bug to Apple told CNN Business.

A hacker would need physical access to a target’s phone to complete the hack — but once it is in their possession they could bypass Apple’s standard security features like facial I.D. Once they have done so, they can access the phone’s address book and see information for contacts stored on the phone, as well as indications of the most recent contacts with whom the phone’s owner had been communicating.

Jose Rodriguez, a cybersecurity enthusiast, living in the Canary Islands, contacted Apple on July 3rd suggesting that he had found a “passcode bypass” and asked if his findings would be eligible for an Apple Security Bounty — a program that rewards security researchers who bring bugs to Apple’s attention.

Apple promptly followed-up on Rodriguez’s tip and company staff had several calls with the researcher during which he walked them through the vulnerability on a beta version of the software, Rodriguez said.

Rodriguez provided copies of the emails and phone records of his correspondences with Apple to CNN Business.

Suspecting Apple might not fix the flaw before releasing the new operating system to its customers, Rodriguez last week went public with his findings.

CNN Business was able to replicate the exploit on Tuesday on iPhones that had updated to the official version of iOS 13.

Apple confirmed that the exploit Rodriguez identified would be fixed in the next version of the operating system, iOS 13.1, which is due to be released on September 24th.

The company previously moved the release date for that update forward from September 30th. The company declined to say if Rodriguez’s discovery had prompted the early release.

The-CNN-Wire
™ & © 2019 Cable News Network, Inc., a Time Warner Company. All rights reserved.

We want to hear from you.

Have a story idea or tip? Send it to the KSL NewsRadio team here.

Riverton, Utah, Mayor Trent Staggs, a U.S. Senate candidate endorsed by former President Donald Tru...

Hannah Schoenbaum

Utah GOP picks Trump-backed mayor as nominee to replace Sen. Mitt Romney, but primary foes await

The Utah Republican Party has selected Trent Staggs as its nominee to replace Mitt Romney in the U.S. Senate.

1 hour ago

(Canva)...

Michelle Lee

Is stress hurting your sleep? Here’s what you can do

Let’s Get Moving Host Maria Shilaos spoke with Clinical Psychologist Dr. Kelly Baron to learn how we can sleep better when under stress.

2 hours ago

Police lights pictured. Man arrested after. allegedly killing his father...

Derrick Jones

Man arrested after allegedly killing his elderly father

An incident in West Valley City led to the arrest of Jeremy Pulver, who stands accused of killing his father.

13 hours ago

Utah state Rep. Phil Lyman, a candidate for governor...

HANNAH SCHOENBAUM Associated Press

Utah GOP nominates Lyman for governor’s race, he’ll meet Gov. Cox in a primary

State Rep. Phil Lyman was selected as the Utah Republican gubernatorial nominee at the party's convention Saturday.

16 hours ago

Utah Republican legislative candidates advanced in several races during the state GOP convention Sa...

Daniel Woodruff

Utah Republican legislative candidates advance out of state convention

Utah Republican legislative candidates advanced in several races during the state GOP convention on Saturday.

19 hours ago

Richfield City police said Jack Becker, the driver of a utility task vehicle, died of injuries he s...

Kennedy Camarena

Richfield City Police identify UTV driver who died in car crash

Richfield City Police have named the driver of a utility task vehicle after he was involved in a car crash and later died at the hospital.

22 hours ago

Sponsored Articles

a doctor putting her hand on the chest of her patient...

Intermountain Health

Intermountain nurse-midwives launch new gynecology access clinic

An access clinic launched by Intermountain nurse-midwives provides women with comprehensive gynecology care.

Young couple hugging while a realtor in a suit hands them keys in a new home...

Utah Association of Realtors

Buying a home this spring? Avoid these 5 costly pitfalls

By avoiding these pitfalls when buying a home this spring, you can ensure your investment will be long-lasting and secure.

a person dressed up as a nordic viking in a dragon boat resembling the bear lake monster...

Bear Lake Convention and Visitors Bureau

The Legend of the Bear Lake Monster

The Bear Lake monster has captivated people in the region for centuries, with tales that range from the believable to the bizarre.

...

Live Nation Concerts

All the artists coming to Utah First Credit Union Amphitheatre (formerly USANA Amp) this summer

Summer concerts are more than just entertainment; they’re a celebration of life, love, and connection.

Mother and cute toddler child in a little fancy wooden cottage, reading a book, drinking tea and en...

Visit Bear Lake

How to find the best winter lodging in Bear Lake, Utah

Winter lodging in Bear Lake can be more limited than in the summer, but with some careful planning you can easily book your next winter trip.

Happy family in winter clothing at the ski resort, winter time, watching at mountains in front of t...

Visit Bear Lake

Ski more for less: Affordable ski resorts near Bear Lake, Utah

Plan your perfect ski getaway in Bear Lake this winter, with pristine slopes, affordable tickets, and breathtaking scenery.

A flaw in iOS 13 can expose your contact details, and Apple’s known about the problem since July