Apple's iPhone X Face ID facial recognition system was found to have security vulnerabilities, including the ability for identical twins to unlock each other's devices and various technical malfunctions that prevented the system from working properly.
Apple released the iPhone X in late 2017 featuring Face ID, a facial recognition system that replaced Touch ID as the primary biometric authentication method. The system uses infrared light and over 30,000 invisible dots to create a 3D map of users' faces. Multiple security issues were discovered shortly after release. Several sets of identical twins were able to successfully unlock each other's iPhone X devices despite only one twin registering their face with the system. Testing by outlets like Mashable found that Face ID failed to distinguish between identical twins in multiple cases, while Business Insider found mixed results. Additionally, numerous users reported technical failures where Face ID stopped working entirely, displaying 'Face ID not available' error messages, particularly affecting iPhone XS Max users running iOS 12.1. A Chinese woman named Yan reported that her colleague could unlock her iPhone X, and Apple provided a replacement device that had the same issue. Apple had previously acknowledged that Face ID's security would be lower for twins and siblings with similar facial features, stating the probability drops from 1 in 1 million for random individuals. The company recommended that children under 13 not use Face ID due to less developed facial features. Various workarounds and fixes were suggested, including soft resets, but the fundamental twin vulnerability remained across multiple iPhone X models.
Domain classification, causal taxonomy, severity scores, and national security assessments were LLM-classified and may contain errors.
Vulnerabilities that can be exploited in AI systems, software development toolchains, and hardware, resulting in unauthorized access, data and privacy breaches, or system manipulation causing unsafe outputs or behavior.
AI system
Due to a decision or action made by an AI system
Unintentional
Due to an unexpected outcome from pursuing a goal
Post-deployment
Occurring after the AI model has been trained and deployed