Companies that let staff use iPhones and iPads for business have been warned that hackers could steal passwords from the device in just six minutes even if its lock is enabled.
The hack, which could seriously compromise a corporation's critical infrastructure, was uncovered by experts in Germany and allows attackers to break into a lost or stolen phone simply by removing its SIM card and following a brief procedure, the Sydney Morning Herald reported on Friday.
Experts at Germany's state-sponsored research institute Fraunhofer SIT said in a statement: "Within six minutes the institute's staff were able to render void the iPhone's encryption and decipher the passwords stored on it.
"If the iPhone is used for business purposes then the company's network security may be at risk as well. Only companies prepared for such an attack will be able to reduce their risk."
The attack targets Apple's password management system, known as a "keychain", which scrambles all passwords and login information on the iPhone.
It can compromise iPhones and iPads with the latest software version installed even if they have the software "screen lock" turned on.
Once an attacker has access to the phone, the first step is to install "jailbreaking" software, which a small number of iPhone owners do voluntarily so they can download apps unauthorised by Apple.
From here, the attacker downloads a programme on to the phone that is able to decrypt passwords held on it, most notably for Google Mail accounts and for private company networks.
"As soon as attackers are in the possession of an iPhone or iPad and have removed the device's SIM card, they can get hold of email passwords and access codes to corporate VPNs (virtual private networks) and WLANs (wireless local area networks) as well," the researchers said in a statement.