<2025-09-18>
Summary ATTACH
It is possible to confirm whether a Phone Number/Email is saved in an locked iPhone (after first unlock) by using Spotlight Search.
Prerequisites
Physical access to a locked iPhone with default configuration after first unlock (incl. Lockdown Mode (https://support.apple.com/en-us/105120)).
Steps to Reproduce
- Use Spotlight Search to search for a Phone Number (with proper country coding e.g., +36 for Hungary)/Email Address.
- If the Phone Number/Email Address is in the Contact List, there will be no option to Call/Email them (only search in safari shows up).
Exploitation ATTACH
Saved Contact Info (Phone Number ending in 37
, Email ending in 02@gmail.com
):
Only Safari Search shows up when a Saved Contact is hit:
Add Email shows up when an Unsaved Contact is hit:
It's the same with Phone Numbers…
Phone Number is SAVED IN Contact List:
Phone Number is NOT saved in Contact List:
Possible Remediation: Only show Add Number/Email option after unlocking the device to avoid Contact Information Disclosure.
Response ATTACH

- Haha it's just intentional behavior if u want securti✨ just disable the function and get fkd retard