Anyone else on #iPhone #iOS 26.5 (latest)?
-
Anyone else on #iPhone #iOS 26.5 (latest)?
I found a privacy bug.
When the phone is locked, I am able to open the camera as usual to take photos, and I found I can also can view and manipulate the camera roll. It was not possible to do this on past versions of iOS.
This feels like a major privacy and safety issue. Anyone with physical access to a phone can view and delete someone's pictures. Abusers, government, anyone.
I've reported it, but I'd appreciate boosts to help spread the word. And confirmation, of course, if you see the same thing.
Editing to clarify: this seems like a sneaky unlock rather than open access to the camera. However, the behavior has changed from what I used to get in past versions of iOS.
Edit #2: there is a way to require the Photos app (your camera roll) to require Face ID so you don't see this behavior. I believe this should be the default.
@Emily For what it’s worth, on my 13 Pro, running 26.5:
From the lock screen, I can take a picture (as is normal), but it only shows the camera roll from that particular session. It doesn’t show me my saved camera roll, and if I close the camera app and reopen it, I don’t see the photos just taken. I need to login and go the the full camera roll.
Edit to correct iOS version
-
Anyone else on #iPhone #iOS 26.5 (latest)?
I found a privacy bug.
When the phone is locked, I am able to open the camera as usual to take photos, and I found I can also can view and manipulate the camera roll. It was not possible to do this on past versions of iOS.
This feels like a major privacy and safety issue. Anyone with physical access to a phone can view and delete someone's pictures. Abusers, government, anyone.
I've reported it, but I'd appreciate boosts to help spread the word. And confirmation, of course, if you see the same thing.
Editing to clarify: this seems like a sneaky unlock rather than open access to the camera. However, the behavior has changed from what I used to get in past versions of iOS.
Edit #2: there is a way to require the Photos app (your camera roll) to require Face ID so you don't see this behavior. I believe this should be the default.
@Emily I’m only able to view the pictures I took in that session. Not previously taken pictures. Are you able to see previous photos and have you made sure you’re not face-IDing into your phone?
-
@Emily I’m only able to view the pictures I took in that session. Not previously taken pictures. Are you able to see previous photos and have you made sure you’re not face-IDing into your phone?
@partridge I am sure I'm not unlocking my phone.
-
@partridge I am sure I'm not unlocking my phone.
@Emily I get the big “no photos or videos”



-
@Emily I get the big “no photos or videos”



@partridge Do you have your Photos app set to require Face ID to view?
If I do that, I don't see the past photos. I think that behavior used to be default, and I think it should be again.
-
To reproduce:
1. Enable Face ID.
2. Do not unlock the phone. Only swipe to open the camera. Do this with your face visible to the front-facing camera.
3. Check your camera roll.Unlocking the camera did not unlock access to past pictures in prior versions of iOS.
@Emily I think you’re still unlocking the phone by looking it up I tried with the phone facing away from my face but still visible, and I couldn’t access the roll.
-
It's now configurable to require Face ID to view your Photos app. It used to be a default that you had to use Face ID, instead of the other way around. And I think that it should be private by default.
-
Same. I can open the camera without unlocking and take a photo/s and then open the camera roll and it includes only photo/s taken since opening the camera and nothing older. Which is the same behaviour I remember from before upgrading.
I assume all the people boosting this tried it and were able to reproduce it, wouldn't want to think mastodonians would be boosting something like this without trying it.
FWIW, the first time I tried to reproduce this, I thought I had! 🫣 , but no, I'd accidentally unlocked my own phone, oops.
@SuperSluether @tk51688 @EmilyIt's now configurable to require Face ID to view your Photos app. It used to be a default that you had to use Face ID, instead of the other way around. And I think that it should be private by default.
-
@Emily I think you’re still unlocking the phone by looking it up I tried with the phone facing away from my face but still visible, and I couldn’t access the roll.
I'm not doing the action to unlock my phone, though, I'm opening the camera with my face in front of it. Two different gestures. But the phone is taking it as an unlock.
It's now configurable to require Face ID to view your Photos app. It used to be a default that you had to use Face ID, instead of the other way around. And I think that it should be private by default.
-
R relay@relay.infosec.exchange shared this topic
-
I'm not doing the action to unlock my phone, though, I'm opening the camera with my face in front of it. Two different gestures. But the phone is taking it as an unlock.
It's now configurable to require Face ID to view your Photos app. It used to be a default that you had to use Face ID, instead of the other way around. And I think that it should be private by default.
@Emily Swiping up isn’t about unlocking your phone, it’s about getting to the Home Screen. Looking at your phone unlocks it.
To test, hold the phone at an angle and push the sleep switch to wake it. You’ll see a lock icon. Look at the phone with no other actions and you’ll see the lock icon disappear.
-
Anyone else on #iPhone #iOS 26.5 (latest)?
I found a privacy bug.
When the phone is locked, I am able to open the camera as usual to take photos, and I found I can also can view and manipulate the camera roll. It was not possible to do this on past versions of iOS.
This feels like a major privacy and safety issue. Anyone with physical access to a phone can view and delete someone's pictures. Abusers, government, anyone.
I've reported it, but I'd appreciate boosts to help spread the word. And confirmation, of course, if you see the same thing.
Editing to clarify: this seems like a sneaky unlock rather than open access to the camera. However, the behavior has changed from what I used to get in past versions of iOS.
Edit #2: there is a way to require the Photos app (your camera roll) to require Face ID so you don't see this behavior. I believe this should be the default.
@Emily I have just tried this on my partner’s locked phone and I could not get into the camera roll beyond photos taken that session.
I’ve noticed it kicks in Face ID right away when I try this on my own phone, so I have access to my photos. But if I do this from locked and cover the island/sensor it won’t work. I’m on iOS 26.5.
-
Anyone else on #iPhone #iOS 26.5 (latest)?
I found a privacy bug.
When the phone is locked, I am able to open the camera as usual to take photos, and I found I can also can view and manipulate the camera roll. It was not possible to do this on past versions of iOS.
This feels like a major privacy and safety issue. Anyone with physical access to a phone can view and delete someone's pictures. Abusers, government, anyone.
I've reported it, but I'd appreciate boosts to help spread the word. And confirmation, of course, if you see the same thing.
Editing to clarify: this seems like a sneaky unlock rather than open access to the camera. However, the behavior has changed from what I used to get in past versions of iOS.
Edit #2: there is a way to require the Photos app (your camera roll) to require Face ID so you don't see this behavior. I believe this should be the default.
@Emily Also ein Fremder kann zwar ein Foto „knipsen“. Aber wie du festgestellt hast, muss für den Zugriff auf alle Fotos, erst das Gerät entsperrt sein.
-
Anyone else on #iPhone #iOS 26.5 (latest)?
I found a privacy bug.
When the phone is locked, I am able to open the camera as usual to take photos, and I found I can also can view and manipulate the camera roll. It was not possible to do this on past versions of iOS.
This feels like a major privacy and safety issue. Anyone with physical access to a phone can view and delete someone's pictures. Abusers, government, anyone.
I've reported it, but I'd appreciate boosts to help spread the word. And confirmation, of course, if you see the same thing.
Editing to clarify: this seems like a sneaky unlock rather than open access to the camera. However, the behavior has changed from what I used to get in past versions of iOS.
Edit #2: there is a way to require the Photos app (your camera roll) to require Face ID so you don't see this behavior. I believe this should be the default.
@Emily I use a passcode (I refuse to use Face ID) and I just tested this on my iPhone with the latest update. I can only edit the photo I take and can’t view any other without being prompted to use my passcode.
-
@Emily Also ein Fremder kann zwar ein Foto „knipsen“. Aber wie du festgestellt hast, muss für den Zugriff auf alle Fotos, erst das Gerät entsperrt sein.
Except if they have access to your face, and if you have gone in and set the Photos app to require Face ID.
I do believe the more private setting used to be the default, and should be the default.
-
Anyone else on #iPhone #iOS 26.5 (latest)?
I found a privacy bug.
When the phone is locked, I am able to open the camera as usual to take photos, and I found I can also can view and manipulate the camera roll. It was not possible to do this on past versions of iOS.
This feels like a major privacy and safety issue. Anyone with physical access to a phone can view and delete someone's pictures. Abusers, government, anyone.
I've reported it, but I'd appreciate boosts to help spread the word. And confirmation, of course, if you see the same thing.
Editing to clarify: this seems like a sneaky unlock rather than open access to the camera. However, the behavior has changed from what I used to get in past versions of iOS.
Edit #2: there is a way to require the Photos app (your camera roll) to require Face ID so you don't see this behavior. I believe this should be the default.
@Emily@infosec.exchange I just tried it. I think maybe the iPhone is unlocking with FaceID:
- iPhone locked, opened the camera, the camera roll was available, as you said.
- iPhone locked, I put my finger on top of the front camera, opened the camera, the camera roll was empty.
I haven’t tried it with someone else’s face. -
R relay@relay.publicsquare.global shared this topic
-
@tk51688 The thing is that this behavior - viewing photos from before I opened the camera - is a change from past versions of iOS.
I agree that if I am not in view of the camera, the behavior is the same as I expect. But I've been using this feature for years, with my face visible to the cameras, and I wasn't able to view older photos then.
-
Anyone else on #iPhone #iOS 26.5 (latest)?
I found a privacy bug.
When the phone is locked, I am able to open the camera as usual to take photos, and I found I can also can view and manipulate the camera roll. It was not possible to do this on past versions of iOS.
This feels like a major privacy and safety issue. Anyone with physical access to a phone can view and delete someone's pictures. Abusers, government, anyone.
I've reported it, but I'd appreciate boosts to help spread the word. And confirmation, of course, if you see the same thing.
Editing to clarify: this seems like a sneaky unlock rather than open access to the camera. However, the behavior has changed from what I used to get in past versions of iOS.
Edit #2: there is a way to require the Photos app (your camera roll) to require Face ID so you don't see this behavior. I believe this should be the default.
@Emily I cannot verify this bug exists. when I open the camera without unlocking and try to press where the photo reel button would be, it says "No photos or videos."
The only thing I might mention is that I keep my phone on lockdown mode. I also note i cannot "swipe" the camera open. I must long press the camera button on the lower right of the lock screen.
edit 2: I see now, this is an issue. While the phone is locked and without face ID present you can open the camera and while the normal camera reel button in the lower left does say "No photos or videos" when pressed, but it also reveals a new photo reel button at the top right which indeed does allow people to view photos on a locked device.
edit 3: now I can't get it to show me photos or videos anymore. I think it may have been detecting my face previously even though I was pointing the camera away from me.
-
Anyone else on #iPhone #iOS 26.5 (latest)?
I found a privacy bug.
When the phone is locked, I am able to open the camera as usual to take photos, and I found I can also can view and manipulate the camera roll. It was not possible to do this on past versions of iOS.
This feels like a major privacy and safety issue. Anyone with physical access to a phone can view and delete someone's pictures. Abusers, government, anyone.
I've reported it, but I'd appreciate boosts to help spread the word. And confirmation, of course, if you see the same thing.
Editing to clarify: this seems like a sneaky unlock rather than open access to the camera. However, the behavior has changed from what I used to get in past versions of iOS.
Edit #2: there is a way to require the Photos app (your camera roll) to require Face ID so you don't see this behavior. I believe this should be the default.
@Emily
Doesn't work when you disable FaceID or cover front camera. That means, nobody can get to your photos except authorized users.False alarm.
-
Anyone else on #iPhone #iOS 26.5 (latest)?
I found a privacy bug.
When the phone is locked, I am able to open the camera as usual to take photos, and I found I can also can view and manipulate the camera roll. It was not possible to do this on past versions of iOS.
This feels like a major privacy and safety issue. Anyone with physical access to a phone can view and delete someone's pictures. Abusers, government, anyone.
I've reported it, but I'd appreciate boosts to help spread the word. And confirmation, of course, if you see the same thing.
Editing to clarify: this seems like a sneaky unlock rather than open access to the camera. However, the behavior has changed from what I used to get in past versions of iOS.
Edit #2: there is a way to require the Photos app (your camera roll) to require Face ID so you don't see this behavior. I believe this should be the default.
@Emily weird, and scary. But I’m unable to reproduce that, iOS 26.5 on a iPhone SE (3rd gen). Once you start taking pictures you can see only those you took while the phone is locked. Try to get to other photos and the phone prompts to unlock.
-
To reproduce:
1. Enable Face ID.
2. Do not unlock the phone. Only swipe to open the camera. Do this with your face visible to the front-facing camera.
3. Check your camera roll.Unlocking the camera did not unlock access to past pictures in prior versions of iOS.
@Emily Lock screen > Camera > photo roll definitely worked that way for me in iOS 18. I’m pretty sure that’s how it has always worked with Face ID phones, though I don’t have any running software earlier than 26 at this point.
Face ID has always been very low-friction and it uses this to be pretty aggressive about unlocking. The raise-to-wake phones unlock when you pick them up with your face in view, so it’s almost always unlocked before I even start the camera.