<2025-09-18>
Summary ATTACH
Phone Numbers not saved in the contact list can be called from a locked iPhone (after first unlock) by using Spotlight Search.
Prerequisites
Physical access to a locked iPhone with default configuration after first unlock (incl. Lockdown Mode (https://support.apple.com/en-us/105120)).
Steps to Reproduce
- Use Spotlight Search to search for a Phone Number (with proper country codes e.g., +36 for Hungary).
- Tap on the number label itself (not the phone icon) to call arbitrary phone numbers that are not saved in the contact list.
Exploitation ATTACH
Tapping the Phone Number text label itself shown in Spotlight Search results calls the Entered Phone Number. It is also possible to call Premium-Rate Phone Numbers (Phone thievery comeback is real lol💀🥀).
Enter any unsaved Phone Number:
And click on the Phone Number text itself to start calling:


Possible Remediation: As used in the Email sending feature, Calling should also require the user to unlock the device except when calling an emergency number.
Response ATTACH

- Haha it's just intentional behavior if u want securti✨ just disable the function and get fkd retard