Software patches to fix this vulnerability can be used for iPhone 8 and later, iPad Pro, iPad Air 3 and later, iPad 5 and later, and iPad mini 5 and later.

2025/06/2418:50:34 technology 1846
The security vulnerability now patched in Apple iOS and macOS operating systems could enable applications with Bluetooth access to eavesdrop on your conversations with Siri.

Apple says, "The application may be able to record audio using a pair of connected AirPods", adding that it solves the core Bluetooth issue in iOS 16.1 and improves permissions. The credit for the discovery and reporting of the error in August 2022 was the application developer Guillerme Rambo. The vulnerability, known as SiriSpy, has been assigned the identifier CVE-2022-32946.

"Any app that has access to Bluetooth can record your conversation with Siri and audio from the iOS keyboard dictation feature when using AirPods or Beats headset ," Rambo said in an article.

According to Rambo, the vulnerability is related to a service called DoAP, which is included in AirPods for Siri and dictation support, allowing malicious actors to make an application that can connect to AirPods via Bluetooth and record audio in the background.

More complicated is that "no request to access the microphone, the instructions in the control center are only listed' Siri and Dictation', instead of an application that bypasses microphone permissions by talking directly with AirPods via Bluetooth LE.

Software patches to fix this vulnerability can be used for iPhone 8 and later, iPad Pro, iPad Air 3 and later, iPad 5 and later, and iPad mini 5 and later. - DayDayNews

While the attack requires the application to have access to Bluetooth, this restriction can be easily bypassed because users who grant Bluetooth access to the application are unlikely to expect it to also open the door to access conversations and dictation audio with Siri.

However On macOS, the vulnerability can be abused to achieve a complete bypass of the transparency, consent and control (TCC) security framework, which means that any application can record conversations with Siri without asking for any permissions first.

Rambo said the reason for this behavior is due to the lack of rights checks on the BTLE server proxy, the daemon service responsible for handling DoAP audio.

software patches to fix this vulnerability can be used for iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and iPad mini 5th generation and later. This issue has been resolved in all supported macOS versions.

iOS 16.1 update was released on October 24, 2022, fixing a total of 20 vulnerabilities, including kernel vulnerabilities (CVE-2022-42827), which disclosed that the vulnerability is actively exploited in the wild.

Comrades, upgrade the update quickly!

technology Category Latest News

Peninsula All-Media Reporter Lu Hua's live e-commerce, which is in the forefront, is actually not as beautiful as it looks. "The account has been stopped, so we will not do live streaming and selling goods." For short video celebrity anchor Xiong Huohuo, this year's "Double 11" c - DayDayNews

Peninsula All-Media Reporter Lu Hua's live e-commerce, which is in the forefront, is actually not as beautiful as it looks. "The account has been stopped, so we will not do live streaming and selling goods." For short video celebrity anchor Xiong Huohuo, this year's "Double 11" c

Popularity can be bought for money, anchor character design is performed according to scripts, and the price is far from being cut to the lowest... When will the "promotional performance" in Double 11 live broadcast room end