Researchers Demonstrated Method for Bypassing Face ID on an ‘Unconscious’ Victim’s iPhone Using Glasses and Tape

During the Black Hat USA conference in Las Vegas, researchers demonstrated a Face ID bypass method that used glasses and tape to unlock and infiltrate the iPhone of an “unconscious” victim.

According to a report from Threatpost (via iMore), researchers from Tencent aimed to fool the “liveness” detection feature in biometrics, which is meant to distinguish “real” from “fake” features on people.

Liveness detection, said the researchers, detects background noise and response distortion or focus blur, allowing it to make sure that a face is a real face and not a mask. This liveness detection is used by Face ID, and Apple even has an “Attention Aware” feature that makes sure your iPhone doesn’t unlock unless you’re looking at it.

To trick Face ID, the researchers created prototype glasses with black tape on the lenses and white tape inside the black tape to emulate the look of an eye. When putting the glasses over a sleeping victim’s face, they were able to access his iPhone and send themselves money through a mobile payment app.

This method worked because the researchers found that liveness detection works differently with glasses and essentially doesn’t extract 3D information from the eye area when glasses are worn.

They discovered that the abstraction of the eye for liveness detection renders a black area (the eye) with a white point on it (the iris). And, they discovered that if a user is wearing glasses, the way that liveness detection scans the eyes changes.

“After our research we found weak points in FaceID… it allows users to unlock while wearing glasses… if you are wearing glasses, it won’t extract 3D information from the eye area when it recognizes the glasses.”

An attacker attempting to use this method in the real world would need a victim that’s sleeping or unconscious, access to that victim’s iPhone, and then glasses would need to be placed over the eyes without waking the person up. It’s worth noting that this isn’t a situation most people are likely to run into, and there’s also no secondary research on this alleged method this time.

To mitigate the eye detection loophole in the future, researchers suggested biometrics manufacturers add identity authentication for native cameras and “increase the weight of video and audio synthesis detection.”

Apple has designed Face ID with easy access disabling measures for situations where a person might be coerced or forced into unlocking an iPhone with facial recognition. Pressing on the sleep/wake button of a Face ID-enabled iPhone five times in rapid succession brings up an emergency SOS screen that automatically disables Face ID and requires a passcode to be entered before Face ID works again. Pressing and holding the side/top button and a volume button also works on the iPhone and the iPad Pro.

Tag: Face ID
This article, “Researchers Demonstrated Method for Bypassing Face ID on an ‘Unconscious’ Victim’s iPhone Using Glasses and Tape” first appeared on MacRumors.com

Discuss this article in our forums

MacRumors-All?d=6W8y8wAjSf4 MacRumors-All?d=qj6IDK7rITs

Related posts

Latest posts

Apple’s Vision Pro is getting the M5 chip, but that’s not what it really needs

Apple’s M5 chip is coming to the Vision Pro, but that’s not the change the headset really needs. Instead, Apple should be prioritizing a more affordable model.

This music app is doing something different in the Apple App Store

A new music app called Practice Pro has decided against the popular freemium model, and gone in a different direction to attract downloads.

The U.K. wants unchecked access to all iPhones worldwide

Using an infamous legal provision, the UK government has reportedly ordered Apple to let it access encrypted cloud data of all iPhone users across the globe.

This One UI 7 update just made my Galaxy S25 Ultra way more fun

Good Lock's updated Home Up module brings new ways to experiement with your home screen on the Galaxy S25 series, and I'm hooked.

Your smartwatch will soon be able to detect signs of heart failure

Fresh research details a method than can detect congestive heart failure (CHF) using smartwatch ECG data with an impressive 90% accuracy in patients.

This Acer Predator gaming PC with RTX 4070 Ti Super is $350 off

The Acer Predator Orion 5000 gaming PC, featuring the Nvidia GeForce RTX 4070 Ti Super graphics card and 32GB of RAM, is on sale from Best Buy at $350 off.

New iPad Air incoming? There’s a low stock warning

The next iPad Air could be revealed in just a few weeks.

Samsung might return to all-Exynos for its Galaxy S26 lineup

Samsung has seen successful early yields with the Exynos 2600, its in-house chip slated for use with the Galaxy S26.

Google Messages might let you unsend awkward messages in RCS chats

Google Messages could receive a "delete for everyone" feature, allowing you to recall messages, but only in RCS enabled chats.

Grab this Lenovo Legion gaming PC while it’s under $1,000

The Lenovo Legion Tower 5 Gen 8 gaming PC with the AMD Ryzen 5 7600 processor, AMD Radeon RX 7600 graphics card, and 16GB of RAM is a steal for under $1,000,