Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

Flaw in Walkie-Talkie App on Apple Watch Allows Spying

Apple has disabled the Walkie-Talkie app on the Apple Watch after learning of a serious vulnerability that can be exploited to spy on users.

Apple has disabled the Walkie-Talkie app on the Apple Watch after learning of a serious vulnerability that can be exploited to spy on users.

The Walkie-Talkie app installed on the Apple Watch allows users to communicate with other users with a compatible Watch just as they would through a traditional walkie-talkie — you press a button to talk and release it when you’re ready for the other party to talk.

Walkie Talkie app vulnerability allows spying

According to TechCrunch, Apple has temporarily disabled the app after someone informed the company of a security hole through its vulnerability disclosure program. Until Apple releases a patch, the application will continue to be installed on watches, but it will not work.

The vulnerability reportedly allows an attacker to use another user’s iPhone as a listening device, but no other details have been made public.

“Although we are not aware of any use of the vulnerability against a customer and specific conditions and sequences of events are required to exploit it, we take the security and privacy of our customers extremely seriously,” Apple stated. “We concluded that disabling the app was the right course of action as this bug could allow someone to listen through another customer’s iPhone without consent.”

The news comes a few months after Apple disabled the Group feature in FaceTime due to a vulnerability that could have been exploited to spy on users through their device’s microphone and camera. Lawmakers and state authorities raised concerns about how Apple handled the flaw.

Advertisement. Scroll to continue reading.

Related: Apple Claims Parental Control Apps Removed Due to Use of MDM

Related: Apple Steps in: Removes Zoom Web Server From All Macs

Related: Apple Patches SQLite, WebKit Bugs in iTunes and iCloud for Windows

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.