Skip to main content

Hackers can control Google Now and Siri through your headphones

apple homekit bug siri idevices switch
Image used with permission by copyright holder
Many people love their voice assistants, whether it be Siri, Google Now, or Cortana. However, they may not be the most secure feature on your smartphone. As it turns out, it is possible to control both Siri and Google Now through silent radio signals from as far away as 16 feet. A pair of French information security researchers at ANSSI discovered the trick, Wired reports.

The scenario involves targeting a phone that has microphone-enabled headphones plugged into its headphone jack. The hackers use a laptop with the open-source GNU Radio software onboard, a USRP software-based radio, an amplifier, and an antenna to generate electromagnetic waves. The attacker can then exploit the headphone wire itself, simulating audio to make it seem as though it is coming from the microphone. From there, the attacker can control the phone remotely from as far as 16 feet away and ask the digital assistant to perform any action that it’s capable of doing. That includes making calls, navigating the Web, sending texts, and so on.

Hackers could even turn your phone into a listening device to spy on your communications, send the browser to a site with malware, or issue spam and phishing messages through your email and social media accounts. The simple brilliance of the hack shows once again how hackers can help expose problems with some of the most common and trusted technology.

Of course, the hack does have its limits. Hackers can only target phones that have microphone-equipped headphones or earbuds plugged in. It doesn’t work if users don’t have Google Now enabled from their lockscreens, or if they have Google Now programed to respond only to their voice. Now that Siri only responds to the voice of the phone’s owner in iOS 9 on the iPhone 6S, it won’t work on the new iPhones, either. Additionally, anyone who looks at their phone regularly would probably see unauthorized voice commands being carried out on their phone — it’s not exactly a discrete hack.

Regardless, the researchers have pointed out that it’s still a vulnerability that could be exploited easily, especially in public spaces where people congregate.

To protect users’ phones against hacks, the security community frequently recommends that users disable the voice-activated assistants from appearing on the default screen, though most people aren’t willing to sacrifice the convenience of the feature. Additionally, the researchers suggest that if Apple and Google allowed users to set their own activation word like the Moto X does, hackers wouldn’t be able to activate Siri or Google Now, unless they knew your specific name or phrase. Of course, that’s something the tech giants will have to consider — not the user. In regards to this particular headphone jack hack, the researchers suggest microphone cords with heavier shielding inside.

For some time, security advocates have been preaching about the hackable potential of our phone’s voice-activated digital assistants. Quite recently, an embarrassing hack of the iOS 9 lock screen involved tricking Siri into giving up contacts and other information. That flaw has since been fixed in a recent update, but the question of voice assistant hackability is still a serious one.

John Casaretto
Former Digital Trends Contributor
John is the founder of the security company BlackCert, a provider of SSL digital certificates and encryption products. A…
Should you buy the Google Pixel 8 now or wait for the Pixel 9?
The Google Pixel 8's screen.

Now far from being the obscure secret of the mobile industry, the Pixel has become a household name, thanks to Google's insistence on delivering a solid Android experience, along with one of the best smartphone cameras you can buy. The current pinnacle of that line is the Google Pixel 8, which offers everything we want from a Google smartphone. It's fast, gets updates on day one, and has a camera that delivers stunning shots.
The Google Pixel 8 was revealed in October 2023, which means it's fast approaching its one-year birthday. But celebrations aren't likely to be in the cards, not when there's likely to be a shiny new phone to distract us. Google has confirmed the Google Pixel 9's existence, and that means prospective Pixel 8 buyers now have a choice to make: buy the Pixel 8 now, or endure an agonizing wait and see what the Pixel 9 can offer.
It's a tough choice, but we're here to help make it a little easier. While we don't know for sure what the Pixel 9 will bring to the table, we have a lot of leaks and rumors to help us make a more informed choice.
So, should you buy the Google Pixel 8 now or wait for the Pixel 9? Read on to find out.

Google Pixel 9 vs. Pixel 8: design
Google Pixel 8 Andy Boxall / Digital Trends

Read more
Google Gemini is now a lot more helpful on Android phones
Google Gemini running on an Android phone.

Google Gemini is getting a little bit smarter thanks to a small change recently discovered by 9to5Google. The AI assistant will now answer “general questions” even if your Android device is locked.

According to a Google support page, commands like “What’s the weather?” once required you to open your phone first. However, Google now lets you “get answers from Gemini without unlocking your device.”  Previously, Gemini could only control things like alarms, timers, and media while your phone was locked.

Read more
Update your Google Pixel phone right now to fix a big security issue
A person holding the Google Pixel 8a

Google just rolled out its July security update for Pixel devices. While last month's Feature Drop added some cool features, like Gemini Nano on more devices, this month's update addresses a critical security vulnerability. So, if you have a Google Pixel device from the Pixel 5a and later with Android 14, make sure to update it as soon as possible.

What’s the critical security issue? It’s known as CVE–2024–31320, which Google says, under certain conditions, allows third-party apps (“3p”) to bypass user prompts. If you have seen this happening on your Pixel device, then you should be aware that it’s not a good thing to have. So make sure you grab the July security update ASAP.

Read more