Android Facial Recognition Flaw Allows Unauthorized Access via Photos

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Consumer group Which? found that 64% of Android smartphones tested since 2022 can be unlocked using a printed photo, exposing a major security flaw in AI-based facial recognition systems. This vulnerability affects flagship models and risks user privacy and data security in the UK.[AI generated]

Why's our monitor labelling this an incident or hazard?

The facial recognition systems are AI systems that infer from biometric input to authenticate users. The article documents that 21 phone models' facial recognition can be spoofed by simple printed photos, which directly compromises user security and privacy. This is a realized harm scenario, not just a potential hazard, as it enables unauthorized access to personal data and accounts. The lack of adequate warnings exacerbates the harm. Hence, this event meets the criteria for an AI Incident due to direct harm caused by the AI system's malfunction in security authentication.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Consumer productsDigital security

Affected stakeholders
Consumers

Harm types
Human or fundamental rights

Severity
AI incident

AI system task:
Recognition/object detection


Articles about this incident or hazard