Vulnerability in iOS and macOS Allowed Eavesdropping on Siri Conversations

A recently patched vulnerability in Apple iOS and macOS, dubbed SiriSpy, allowed apps with Bluetooth access to eavesdrop on user conversations with Siri, as well as record audio when AirPods or Beats are connected to an Apple device.

让我提醒你,我们也写过 Apple Safari Developers Patch 9-Year-Old Vulnerability for the Third Time.

The problem was discovered in August by developer Guilherme Rambo, who created the AirBuddy app, which makes it easy to connect AirPods, Beats and other Bluetooth accessories to Apple devices. 那是, Rambo spends a lot of time working with AirPods, Beats and so on.

Any app with Bluetooth access can record your Siri conversations and Dictation-related audio when using AirPods or Beats. This happens without asking for permission to access the microphone, and the app does not leave any trace of the microphone being tapped.says the developer.
Guilherme Rambo

Guilherme Rambo

According to Rambo, the issue was related to the DoAP service that AirPods possess to support Siri and Dictation. 实际上, this allowed the attacker to create an application that would work with AirPods via Bluetooth and record audio in the background. The problem was exacerbated by the fact that there was no request for access to the microphone, and onlySiri & Dictationwas displayed in the Control Center, and not an application that bypasses permissions and directly communicates with AirPods via Bluetooth LE.

While on iOS, the attack required granting the app access to Bluetooth, but the researcher says it’s not that much of a problem. After all, users who provide such access to the application are unlikely to expect that after that it will be able to eavesdrop on conversations with Siri and everything said within the framework of Dictation.

In macOS, even this limitation was missing, and the exploit could be used to completely bypass the Transparency, Consent and Control defence system. The reason is in the lack of checks for the BTLEServerAgent daemon responsible for processing DoAP audio.

On macOS, apps can record your Siri conversations or Dictation audio without any permission requests at all. Even worse, this particular exploit also allows the app to request DoAP audio on demand, without having to wait for the user to speak to Siri or use dictation.Rambo wrote.

This issue ended up being CVE-2022-32946, and Apple fixed it this week with the release of iOS 16.1. The researcher received a $7,000 reward from the company for discovering the vulnerability.

关于作者

卡琳娜·威尔逊

随着超过 10 多年在线和印刷媒体写作经验, 我是提供清晰且引人注目的文案的专家.

我曾为一家领先的 SEO 文案机构撰写文章,也为一些英国最知名的品牌撰写文章, 杂志和报纸.

发表评论