ID: 142997


Date: 2019-07-11

Eavesdropping flaw prompts Apple to suspend Walkie-Talkie app

Apple Watch app can let attackers listen to iPhone mic without permission. Apple has suspended use of the Walkie-Talkie app in the Apple Watch until the company fixes a recently discovered vulnerability that could let someone listen to a persons iPhone without permission, news site TechCrunch reported. The Walkie-Talkie app allows people who accept an invitation to talk with friends in real-time without the hassle of making a phone call. Parties press a button when speaking and release it to hear what the other party says. Apple introduced the feature last year as part of its WatchOS 5 update. Apple told TechCrunch that the flaw could allow someone to listen through another partys iPhone without consent. Apple didnt provide specifics of the vulnerability or exactly how it could be exploited. The company said it learned of the vulnerability through its vulnerability reporting page. Apple apologized for the temporary suspension while engineers investigate and fix the issue. In a statement issued to TechCrunch, Apple representatives wrote: We were just made aware of a vulnerability related to the Walkie-Talkie app on the Apple Watch and have disabled the function as we quickly fix the issue. We apologize to our customers for the inconvenience and will restore the functionality as soon as possible. Although we are not aware of any use of the vulnerability against a customer and specific conditions and sequences of events are required to exploit it, we take the security and privacy of our customers extremely seriously. We concluded that disabling the app was the right course of action as this bug could allow someone to listen through another customers iPhone without consent. We apologize again for this issue and the inconvenience. Apple failed to take action on the bug for more than a week after receiving emails from a woman who reported that her 14-year-old had found the vulnerability. Apple finally patched the flaw after word of it spread virally on social media and attracted attention from New York Attorney General Letitia James.