That’s what YouTube channel iDeviceHelp has discovered, and they’ve published a video showing how the exploit works. An attacker would need to have physical access to an iPhone to even have a chance, and from there it’s a combination of calling, sending a message, and Siri to access contact information present on the device without needing to input a passcode.
Take a look at the video below for instructions on how to try it yourself. The trick has been shared with Apple and will likely be addressed in a future software update.
The attacker can use the keyboard to input the first letter of a contact name, and then select the Info option that shows up, gaining access to that contact’s info card while the phone remains, technically, locked the whole time.