UPDATED: Up to iOS/iPadOS 26.0.1, 18.7.1, 17.7.10, 16.7.12, 15.8.5, 14.8.1, 13.7 & 12.5.7 (Sep 30, 2025)
The iOS mobile platform has been subject to numerous lock screen bypass vulnerabilities across multiple versions during the last years. Although Apple strives to fix these vulnerabilities through various iOS updates (
https://support.apple.com/en-us/HT201222), it is important for information and cyber security professionals, and pen-testers, to pay close attention to the current unfixed lock screen bypass scene at any given time, evaluate its risks, and promote enforcing physical security and tight access controls on iOS devices.
Shameless plug: If you are interested in this kind of technical details and want to learn more,
Raul Siles will be teaching future SANS courses, such as the 6-day "
SANS SEC575: Mobile Device Security and Ethical Hacking" course in:
- (last session) Future SANS SEC575 sessions with Raul Siles in 2026...
Many pen-testers tend to focus more on traffic or network activity analysis and attacks, Mobile Device Management (MDM) and back-end systems auditing, jailbreaking or rooting opportunities, or in-depth mobile applications analysis, leaving unattended scenarios with unauthorised physical access to a target device, or the stolen or loss device threat. However, real incidents constantly confirm unattended or stolen devices with a lock screen bypass vulnerability are a serious threat that should be included, or at least evaluated, when scoping a mobile pen testing assessment.
Throughout the years, I've been researching, testing, and collecting a list of all these iOS lock screen bypass vulnerabilities for pen testing engagements, security presentations, and training sessions. Some of them are related to other hardware components, such as the SmartCover or the SIM card, while others are purely driven by new software features and capabilities, such as Siri, VoiceOver or the new Control Center introduced since iOS 7. Some issues impact only iPads or just iPhones, while others affect them all. History ratifies it is hard for Apple to fully mitigate this threat, as the attack surface is significantly wide, and it even increases with newer versions of the iOS platform.
The following list summarises the history of all the lock screen bypass vulnerabilities that iOS has suffered from iOS 5 to the most recent iOS version (until the last update :-). It also includes links to demos and/or videos associated with each vulnerability. The vulnerabilities have been classified based on the iOS version that provides the appropriate fix. Therefore, iOS versions earlier than the one providing the fix are potentially effected by each vulnerability.
The official number of screen lock bypass related vulnerabilities addressed in each major iOS (and since September 2019, in iPadOS) version are:
- iOS 5.x: 4 vulnerabilities.
- iOS 6.x: 8 vulnerabilities.
- iOS 7.x: 12 vulnerabilities.
- iOS 8.x: 11 vulnerabilities.
- iOS 9.x: 6 vulnerabilities.
- iOS 10.x: 10 vulnerabilities.
- iOS 11.x: 10 vulnerabilities.
- iOS 12.x: 8 vulnerabilities.
- iOS 13.x: 4 vulnerabilities.
- iOS 14.x: 7 vulnerabilities.
- iOS 15.x: 12 vulnerabilities.
- iOS 16.x: 11 vulnerabilities.
- iOS 17.x: 19 vulnerabilities.
- iOS 18.x: 21 vulnerabilities.
- iOS 26.x: 2 vulnerabilities (officially, so far!!!).
NOTE: Throughout this article, iOS refers to both, iOS and iPadOS.
iOS Lock Screen Bypass Vulnerability History
The following list has been sorted by iOS version, starting first with a list of generic lock screen bypasses with no officially recognised CVE associated to them (only for this generic section, entries are sorted by date and the iOS version specified refers to the vulnerable iOS version):
- Generic, not officially recognised by Apple, or still unfixed lock screen bypasses (the iOS version specified for each flaw is the latest version known to be vulnerable):
- Siri (iOS 5, iPhone 4S, Oct 2011): Full phone interaction via Siri and voice commands (send e-mails, make calls, calendar and contacts access, etc); could be avoided disabling Siri via Settings. Ref: http://www.triskt.com/word/2011/10/18/ios-5-siri-authentication-bypass/ Video: http://www.youtube.com/watch?v=UM0Ee4KW5-I
- Digital picture frame (iOS 5, iPad, Oct 2011): Access to all photos from the lock screen; could be disabled via Settings. The digital picture frame is not available anymore since iOS 7. Ref: http://www.groovypost.com/howto/apple-ios-5-security-lock-down-private-photos-picture-frame/
- Phone & Contacts access due to a race condition in SIM card insertion (iOS 5.0.1, iPhone, Feb 2012). Ref: http://www.cultofmac.com/147700/ios-5-security-flaw-allows-access-to-contacts-list-recent-calls-text-messages-without-passcode/ Video: http://www.youtube.com/watch?v=Vhy9_bYVIwk (5.0) Video: http://www.youtube.com/watch?v=eFfDR1T6mMg (5.0.1) Video: http://www.youtube.com/watch?v=IZqY1VaMr_A
- Quick camera access (iOS 5.1, iPhone 4S, Mar 2012): Allows taking pictures; camera icon also available in iOS 5 by double-pressing the Home button. This vulnerability still applies today to iOS 7 and can only be mitigated by restricting access to the camera via Settings. Ref: http://www.cnet.com/how-to/access-the-iphone-camera-from-the-lock-screen-even-quicker-on-ios-5-1/
- Emergency dialer screen (iOS 5.1.1, Jul 2012). Video: http://www.youtube.com/watch?v=12OoO9IdBH4
- Access to photos via Control Center - Calculator (iOS 7 beta 1, Jun 2013). Video: http://www.youtube.com/watch?v=tTewm0V_5ts
- Brute force attacks against incorrect passcode restrictions in Settings (iOS 6, iPad, Jun 2013). Ref: http://www.journaldulapin.com/2013/06/04/brute-force-attack-against-restrictions-code-is-possible-on-ios/ Video: http://www.youtube.com/watch?v=C6md792nMhY
- Apple Touch ID bypass (iOS 7, iPhone 5S, Sep 2013). Ref: http://ccc.de/en/updates/2013/ccc-breaks-apple-touchid Video: http://vimeo.com/75324765
- Make calls via Voice Control (iOS 7, Apr 2014): Siri has to be disabled. Video: http://www.youtube.com/watch?v=0CNh_j46byA
- Bypass time delay for incorrect passcode attempts via iTunes Sync (iOS 7.0-7.1.2, Jun 2014). Video: http://www.youtube.com/watch?v=_rT7o_IXehk
- Exceed the maximum number of failed passcode attempts from the Settings app by setting forward the current time (related to Settings but not to the lock screen; iOS 8.1, Oct 2014). Ref: http://phonerebel.com/new-ios-8-1-bypass-discovered/ Video: https://www.youtube.com/watch?v=JY-SbkwZuxU
- Airplane mode via Control Center and missed call in Notification Center (iOS 7.1.1/7.1.2, Aug 2014): Access to last open app. Ref: http://phonerebel.com/how-to-bypass-ios-7-lockscreen/ Video: http://www.youtube.com/watch?v=Hg9Vy7XzGZY Although the official security content for iOS 8 does not mention a specific fix for this issue, in iOS 8 the vulnerability cannot be exploited. When the missed called notification is selected in airplane mode, it is removed from the Notification Center and the following message is displayed in the lock screen:

- Passcode "Merge App Service" bypass & Siri (iOS 7.1.2, Sep 2014). Video: http://www.youtube.com/watch?v=9gBtJ5tyRgI
- ("Voice hacking") Several information leakages via Siri (iOS 7 & iOS 8, Sep 2014): Post to Facebook, get contact details, see call history last 25), listen recent messages, and get full access to notes. It can be mitigated disabling Siri in the lock screen via Settings. Video: https://www.youtube.com/user/videosdebarraquito/videos Video: http://www.youtube.com/watch?v=NTA8k4tyY78
- Access to message creation, contacts and photos via Control Center and the Clock app (Alarm) when rotation is on (iOS 9 Beta 3, Jul 2015). It can be mitigated disabling Control Center in the lock screen. Video: https://www.youtube.com/watch?v=KEwZSpWT3sI Video: https://www.youtube.com/watch?v=_rAlOHo8f6I
- Siri lock screen bypass (iOS 10.0.1). Video: https://www.youtube.com/watch?v=EVO8ziXT79g
- Access to iMessages, contacts and photos via a FaceTime (or phone) call, a custom message and Siri (plus VoiceOver). Again, this bypass can be mitigated disabling Siri in the lock screen (iOS 10.1.1 & 10.2Beta3 in iPhones and iPads, the discontinued iOS 9.3.5 - iPhone 4S, and back to iOS 8.3...). Video: https://www.youtube.com/watch?v=LWJG5I8xCDU Video: https://www.youtube.com/watch?v=hP3BMyrFBSs (Fixed in iOS 10.2, but not in previous iOS 9.x, or below, versions).
- Siri allows accessing (by reading) the content of (hidden, via "show previews") notifications for third party apps from the lock screen (iOS 11.3 beta - March 20, 2018; similar to CVE-2017-13805 for iOS 11.1). Ref: https://macmagazine.com.br/2018/03/20/bug-de-privacidade-do-ios-faz-a-siri-ler-notificacoes-escondidas-na-tela-bloqueada/ Ref: https://www.macrumors.com/2018/03/22/apple-to-fix-siri-reading-hidden-notifications/
- iOS 11.x passcode bypass services and/or products (iOS 11.3?):
- iOS 12.1: Access to contacts via Siri, FaceTime and airplane mode from the lock screen. Video: https://www.youtube.com/watch?v=ojigFgwrtKs (Fixed in iOS 12.1.1).
- Fake iOS 14.5.1 bypass: Unlocking iOS 14.5.1 without knowing the passcode using the calculator via Control Center. PoC in a TikTok video by imnotjs3: https://www.tiktok.com/@imnotjs3/video/6938226042696109318.
- The PoC is fake, as the mobile device is automatically unlocked by Face ID with a legitimate face while in the Control Center screen and interacting with the calculator.
- If the calculator remains in portrait mode, it means Face ID didn't authenticate a legitimate user. If the calculator goes to landscape mode, it means Face ID unlocked the device with a legitimate user.
- iOS 14.8 / iOS 15RC / iOS 15: Lock screen bypass via Siri and Voice Over (again) allows accessing Notes and other sensitive information.
By iOS version:
- iOS 18.0 (Sep 2024): https://support.apple.com/en-us/121250
- Accessibility: An attacker with physical access to a locked device may be able to Control Nearby Devices via accessibility features (CVE-2024-44171).
- Accessibility: An attacker may be able to see recent photos without authentication in Assistive Access (CVE-2024-40852).
- Siri (2 CVEs): An attacker with physical access may be able to access contacts from the lock screen (CVE-2024-44139) (CVE-2024-44180).
- iOS 18.0.1 (Oct 2024): https://support.apple.com/en-us/121373
- iOS 18.1 (Oct 2024): https://support.apple.com/en-us/121563
- Accessibility: An attacker with physical access to a locked device may be able to view sensitive user information (CVE-2024-44274).
- Siri: An attacker with physical access may be able to access contact photos from the lock screen (CVE-2024-40851).
- Spotlight: An attacker may be able to view restricted content from the lock screen (CVE-2024-44251).
- Spotlight: An attacker may be able to view restricted content from the lock screen (CVE-2024-44235).
- VoiceOver: An attacker may be able to view restricted content from the lock screen (CVE-2024-44261).
- iOS 18.1.1 (Nov 2024): https://support.apple.com/en-us/121752
- iOS 18.2 (Dec 2024): https://support.apple.com/en-us/121837
- VoiceOver: An attacker with physical access to an iPadOS device may be able to view notification content from the lock screen (CVE-2024-54485).
- iOS 18.2.1 (Jan 2025): N/A (This update has no published CVE entries)
- iOS 18.3 (Jan 2025): https://support.apple.com/en-us/122066
- Accessibility: An attacker with physical access to an unlocked device may be able to access Photos while the app is locked (CVE-2025-24141).
- iOS 18.3.1 (Feb 2025): https://support.apple.com/en-us/122174
- Accessibility: A physical attack may disable USB Restricted Mode on a locked device; reports of exploitation in targeted sophisticated attacks (CVE-2025-24200).
- iOS 18.3.2 (Mar 2025): https://support.apple.com/en-us/122281
- iOS 18.4 (Mar 2025): https://support.apple.com/en-us/122371
- Focus: An attacker with physical access to a locked device may be able to view sensitive user information (CVE-2025-30439).
- Kernel: A malicious app may be able to attempt passcode entries on a locked device and thereby cause escalating time delays after 4 failures (CVE-2025-30432).
- MobileLockdown: An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos (CVE-2025-24193).
- Photos: A person with physical access to an iOS device may be able to access photos from the lock screen (CVE-2025-30469).
- Share Sheet: A malicious app may be able to dismiss the system notification on the Lock Screen that a recording was started (CVE-2025-30438).
- Siri: An attacker may be able to use Siri to enable Auto-Answer Calls (CVE-2025-30436).
- Siri: An attacker with physical access may be able to use Siri to access sensitive user data (CVE-2025-24198).
- iOS 18.4.1 (Apr 2025): https://support.apple.com/en-us/122282
- iOS 18.5 (Apr 2025): https://support.apple.com/en-us/122404
- Notes: An attacker with physical access to a device may be able to access notes from the lock screen (CVE-2025-31228).
- iOS 18.6 (Jul 2025): https://support.apple.com/en-us/124147
- iOS 18.6.1 (Aug 2025): N/A (This update has no published CVE entries)
- iOS 18.6.2 (Aug 2025): https://support.apple.com/en-us/124925
- iOS 18.7 (Sep 2025): https://support.apple.com/en-us/125109
- Notes: An attacker with physical access to a device may be able to access notes from the lock screen (CVE-2025-43203). - Not specific to the lock screen, but related -
- iOS 18.7.1 (Sep 2025): https://support.apple.com/en-us/125327
- iOS 26.0 (Sep 2025): https://support.apple.com/en-us/125108
- Notes: An attacker with physical access to a device may be able to access notes from the lock screen (CVE-2025-43203). - Not specific to the lock screen, but related -
- Text Input: Keyboard suggestions may display sensitive information on the lock screen (CVE-2025-24133).
- iOS 26.0.1 (Sep 2025): https://support.apple.com/en-us/125326
NOTE: Since all of these vulnerabilities have not been officially acknowledged by Apple, it is sometimes complex to identify duplicates or missing ones. If you identify any discrepancy, inaccuracies, or additional references or videos, please let me know.
Protecting iOS Devices Against Lock Screen Bypass Vulnerabilities
This extensive list of iOS lock screen bypass vulnerabilities can be exploited by anyone that gets physical access to a target device, even temporarily. It is therefore crucial for both security professionals and pen-testers, as part of their recommendations within pen test reports, to provide countermeasures that mitigate the associated risks. In fact, unless an organization is impeccable in their patching and update process, you are pretty much guaranteed to find an older version of iOS on some of their devices that could lead to a significant finding. And, if the organization employs a Bring Your Own Device (BYOD) policy, again you are ensured of a proliferation of older versions ripe for attack. If you can gather information about the use of such devices, you’ll have a nice finding for your report.
In order to minimize the impact of lock screen bypass vulnerabilities in iOS devices, it is highly recommended to always update the mobile device to the latest iOS version available, which supposedly fixes all the publicly known vulnerabilities, and manually (or though an MDM solution) verify that you really are in the latest and expected iOS version (
http://blog.dinosec.com/2014/06/ios-back-to-future.html).
Besides that, in iOS some of the (current and future) lock screen bypass vulnerabilities can be mitigated by limiting the functionality available in the lock screen. The following list summarizes various recommended configuration options currently available to protect the lock screen on iOS devices (it is outdated, as it applies to iOS version 8, with additional clarifications for iOS 7; however, the concepts can also be applied to newer iOS versions). Of course, turning off these functions can improve security by lowering the attack surface, but also may anger users who aren’t able to utilize the latest gee-whiz features of their devices. Evaluate each of these actions before applying them, as there is always a security versus usability trade off associated to disabling the functionality and features available in the lock screen without requiring the user to enter a passcode. For organizations requiring a high degree of security, though, these hardened configurations should at least be considered:
- Disable Siri (or Voice Dial, if Siri is not enabled; watch out as Music Voice Control is always enabled (*)) when the device is locked: Navigate to "Settings –> Passcode –> Siri (or Voice Dial)" and disable it there ("Allow access when locked: Siri = OFF"):
- Disable Passbook when the device is locked: Navigate to "Settings –> Passcode –> Passbook" and disable it there ("Allow access when locked: Passbook = OFF").
- Disable the Control Center from the lock screen to avoid exposing sensitive controls, such as enabling/disabling the Wi-Fi or Bluetooth interfaces, or even airplane mode: Navigate to "Settings –> Control Center –> Access on Lock Screen = OFF". The multiple controls available in Control Center cannot be customized; therefore it can only be enabled or disabled completely.
- Disable the Notification Center, and specifically, its availability from the lock screen, including Today View (new since iOS 7). In iOS 8, navigate to "Settings –> Passcode –> Allow access when locked:" and disable both "Today" and "Notifications View":
- To accomplish the same task in iOS 7, navigate to "Settings –> Notification Center –> Access on Lock Screen" and disable both, "Notifications View" and "Today View".
- More granular notification settings can be configured for each individual app from the "Include" section of Notification Center. Apps can be completely unlinked from Notification Center by accessing their settings and turning off notifications. In iOS 8, go to "Settings –> Notifications –> –> Allow Notifications = OFF". The app will be moved to the "Do Not Include" section at the bottom (e.g. Twitter app):
- Additionally, the "Show on Lock Screen" setting from the same menu allows defining if the individual app notifications will be available on the lock screen or not. In iOS 7, these and other adjustments in the next set of recommendations were available under "Settings –> Notification Center –> ..." instead. In iOS 7, to unlink an app from the Notification Center go to "Settings –> Notifications –> –> Show in Notification Center = OFF".
- iOS allows answering back a phone call without knowing the passcode by simply swapping the missed call notification available in the lock screen. This behavior cannot be disabled, except by not showing this kind of missed call notification in the lock screen (go to "Settings –> Notifications –> Phone –> Show on Lock Screen = OFF"):
- Similar recommendations apply to other apps that can also show sensitive information in the lock screen, such as Messages. It is recommended to disable the preview of Messages by going to "Settings –> Notifications –> Messages –> Show Previews = OFF" (a specific issue with this setting has been fixed in iOS 8, CVE-2014-4356):
- In order to avoid issues with the SmartCover in iPad devices, its usage can be disabled from "Settings –> General –> Lock/Unlock":
- Disable the camera: In order to remove the quick camera access icon from the lock screen, completely restrict access to the camera via "Settings –> General –> Restrictions" and disable the 'Camera', which will also turn off FaceTime. As there is no other way to simply disable the quick camera access icon, this radical countermeasure is the only option available to avoid someone taking pictures from your iOS device:
- Establish a passcode with at least one alphabetic character, so that the look & feel of the iOS lock screen does not disclose if your passcode is just a PIN (4 digits), is made up of just digits (more than 4), or (preferred option) is alphanumeric.
- ... and remember to frequently physically clean up the screen of your iOS devices too to avoid fingerprints, residues and smudge revealing your passcode :-)
(*): Voice Dial is always enabled since iOS 7.1, and there is no configuration option to disable it, as it was the case in previous iOS versions (e.g. 7.0.x) from "Settings -> General -> Passcode Lock -> Voice Dial" (since iOS 7.1 it should be under "Settings -> Passcode").
All these recommended actions can be manually implemented through the Settings app or (most of them) via a configuration profile that can be pushed to the target iOS mobile devices through an MDM solution. Both offensive attack opportunities and defensive protections are thoroughly covered in the SANS SEC575: Mobile Device Security and Ethical Hacking course, with the main goal of testing and improving the overall security of corporate mobile environments.
NOTE: This article has been crossed posted in both the SANS Pen-Testing Blog (here) and DinoSec's Blog (here) in September 2014.