AIPolicyTracker

AI incident ·

Hackers Break Apple Face ID

24 news reports Snapshot 7 Sep 2026

In brief

An AI system built and deployed by Apple allegedly harmed Apple and Device Owners.

Risk domain
Privacy & Security AI system security vulnerabilities and attacks
Occurred
Coverage
24 reportsSep 2017 - Nov 2017

What happened

Vietnamese security firm Bkav created an improved mask to bypass Apple's Face ID

Laws that address this harm

Policy angle: Classified under Privacy & Security (AI system security vulnerabilities and attacks) in the MIT AI Risk Repository taxonomy; 5 recorded instruments address this use case in Vietnam.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (24)

Titles link to the original publisher; report text is not reproduced here.

  1. We Tried Really Hard To Beat Face ID—and Failed (So Far)
    wired.com · Andy Greenberg, Caitlin Kelly, Emily Dreyfuss
  2. iPhone X Face ID hack uses olives and paper eyes
    gearbrain.com · Alistair Charlton
  3. Hackers Claim to Break Face ID a Week After iPhone X Release
    wired.com · Andy Greenberg, Caitlin Kelly, Emily Dreyfuss
  4. What is Face ID and how does Face ID work?
    alphr.com · Victoria Woollaston
  5. Apple FaceID Hacked
    schneier.com · Bruce Schneier
  6. How to fool Face ID on the iPhone X
    computerworld.com.au · Reuters
  7. Face ID hack is a little concerning
    news.com.au · news.com.au

Who was involved

Alleged deployer
Apple
Alleged developer
Apple
Alleged harmed party
Apple, Device Owners

Classification (MIT AI Risk Repository taxonomy)

Causal entity
AI
Intent
Unintentional
Timing
Post-deployment
Harm level
none
Sectors
information and communication
Countries
VN

Risk entries describing this failure mode

Entries from the MIT AI Risk Repository coded to subdomain 2.2.

  • Privacy loss

    "Privacy loss - Unwarranted exposure of an individual’s private life or personal data through cyberattacks, doxxing, etc."

    A Collaborative, Human-Centred Taxonomy of AI, Algorithmic, and Automation Harms (Abercrombie2024)

  • Jailbreaks and Prompt Injections Threaten Security of LLMs

    "LLMs are not adversarially robust and are vulnerable to security failures such as jailbreaks and prompt-injection attacks. While a number of jailbreak attacks have been proposed in the literature, the lack of standardiz...

    Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  • Exploiting Limited Generalization of Safety Finetuning

    "Safety tuning is performed over a much narrower distribution compared to the pretraining distribution. This leaves the model vulnerable to attacks that exploit gaps in the generalization of the safety training, e.g. usi...

    Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  • “Model Psychology” Attacks

    "LLMs are vulnerable to “psychological” tricks (Li et al., 2023e; Shen et al., 2023), which can be exploited by attackers. Examples include instructing the model to behave like a specific persona (Shah et al., 2023; Andr...

    Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  • Attacking LLMs via Additional Modalities a

    "LLMs can now process modalities other than text, e.g. images or video frames (OpenAI, 2023c; Gemini Team, 2023). Several studies show that gradient-based attacks on multimodal models are easy and effective (Carlini et a...

    Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  • Vulnerability to Poisoning and Backdoors

    "The previous section explored jailbreaks and other forms of adversarial prompts as ways to elicit harmful capabilities acquired during pretraining. These methods make no assumptions about the training data. On the other...

    Foundational Challenges in Assuring Alignment and Safety of Large Language Models (Anwar2024)

  • Hardware Vulnerabilities

    "The vulnerabilities of hardware systems for training and inferencing brings issues to LLM-based applications."

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

  • Network Devices

    "The training of LLMs often relies on distributed network systems [171], [172]. During the transmission of gradients through the links between GPU server nodes, significant volumetric traffic is generated. This traffic c...

    Risk Taxonomy, Mitigation, and Assessment Benchmarks of Large Language Model Systems (Cui2024)

Incidents in the same risk subdomain

All incidents in this subdomain

Other incidents involving Apple

Source record: incident #26 on the AI Incident Database · all 24 reports