PT-2022-21601 · Apple · Ipados+4
Guilherme Rambo
·
Published
2022-10-27
·
Updated
2025-05-06
·
CVE-2022-32946
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
iOS versions prior to 16.1
iPadOS versions prior to 16.1
Description
The issue allowed apps with Bluetooth access to record audio using connected AirPods, potentially capturing conversations with Siri and background sound. This was possible due to a problem with Core Bluetooth and the DoAP service, which supports Siri and Dictation on AirPods. The issue did not require the app to request microphone access permission and would not leave any traces of microphone eavesdropping. The vulnerability could be exploited to bypass the Transparency, Consent and Control (TCC) security system in macOS, allowing any app to record Siri conversations without requesting permissions.
Recommendations
For iOS versions prior to 16.1, update to iOS 16.1 or later to resolve the issue.
For iPadOS versions prior to 16.1, update to iPadOS 16.1 or later to resolve the issue.
As a temporary workaround, consider disabling Bluetooth access for apps that do not require it to minimize the risk of exploitation.
Restrict access to the DoAP service to prevent unauthorized audio recording.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Airpods
Core Bluetooth
Ios
Ipados
Apple Macos