{"id":466537,"date":"2022-10-28T15:18:04","date_gmt":"2022-10-28T13:18:04","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=466537"},"modified":"2022-10-28T15:18:04","modified_gmt":"2022-10-28T13:18:04","slug":"apple-patches-sirispy-vulnerability","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/466537-apple-patches-sirispy-vulnerability.html","title":{"rendered":"Apple patches SiriSpy vulnerability"},"content":{"rendered":"<p>Apple has patched a security flaw that could have let apps on iOS and MacOS with Bluetooth access eavesdrop on Siri conversations.<\/p>\n<p>The Hacker News <strong><a href=\"https:\/\/thehackernews.com\/2022\/10\/apple-ios-and-macos-flaw-couldve-let.html\" target=\"_blank\" rel=\"noopener\">reports<\/a><\/strong> that app developer Guilherme Rambo is credited with uncovering and reporting the bug to Apple in August 2022.<\/p>\n<p>The vulnerability is dubbed SiriSpy and is tracked with the identified CVE-2022-32946, with Apple saying, &#8220;an app may be able to record audio using a pair of connected AirPods&#8221; in its description of the flaw.<\/p>\n<p>Apple said it had addressed the Core BlueTooth issue with improved entitlements in iOS 16.1.<\/p>\n<p>However, Rambo explained that the floor didn&#8217;t only relate to Apple AirPods.<\/p>\n<p>&#8220;Any app with access to Bluetooth could record your conversations with Siri and audio from the iOS keyboard dictation feature when using AirPods or Beats headsets,&#8221; he said in a blog post.<\/p>\n<p>&#8220;This would happen without the app requesting microphone access permission and without the app leaving any trace that it was listening to the microphone.&#8221;<\/p>\n<p>Rambo explained that the flaw relates to Apple&#8217;s DoAP service for Siri and Dictation support included in AirPods.<\/p>\n<p>Essentially, a malicious actor could develop an app that connects to AirPods via Bluetooth and records audio in the background.<\/p>\n<p>According to the report, exploitation requires the app to be granted Bluetooth access. However, most users granting Bluetooth permissions likely won&#8217;t expect that it could allow access to their conversations with Siri and audio from dictation.<\/p>\n<p>Notably, the vulnerability could be more dangerous when exploited in MacOS.<\/p>\n<p>Exploiting the flaw in MacOS could let an attacker bypass the Transparency, Consent, and Control security framework, meaning any app can record Siri conversations without requesting permissions.<\/p>\n<p>Apple says it has patched the Core Bluetooth issue in an update for the iPhone 8 and later, all iPad Pro models, iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later.<\/p>\n<p>It has also patched the issue in all supported versions of MacOS.<\/p>\n<hr \/>\n<h2 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/466397-shoprite-invests-in-privacy-protection-startup-after-customer-data-hack.html\" rel=\"bookmark\">Shoprite invests in privacy protection startup after customer data hack<\/a><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>Apple devices had a Core Bluetooth flaw that allowed apps to record conversations with Siri and audio dictation.<\/p>\n","protected":false},"author":341076,"featured_media":466549,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[38848,605,691,36626,2916],"class_list":["post-466537","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-airpods","tag-apple","tag-ios","tag-macos","tag-siri"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/466537"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=466537"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/466537\/revisions"}],"predecessor-version":[{"id":466599,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/466537\/revisions\/466599"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/466549"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=466537"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=466537"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=466537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}