Skip to content

QIF-T0077

high

IR vascular mapping via Face ID system (NIR hemoglobin absorption imaging)

Tier 4 — Demonstrated (Case Study / Observational)

Legacy status: EMERGING

Apple's Face ID TrueDepth system projects 30,000 infrared dots at 940nm onto the user's face and reads the reflection pattern with an IR camera. At 940nm, photons penetrate skin to a depth of 2-5mm — well into the dermal vascular layer. Oxygenated hemoglobin (HbO2) and deoxygenated hemoglobin (Hb) have different absorption coefficients at 940nm, meaning the reflected dot pattern encodes subsurface vascular topology: arterial vs venous vessels, vessel diameter, branching patterns, and oxygenation gradients. This vascular map is a permanent biometric (unlike facial features, which change with age/surgery/expression) and is unique per individual (even identical twins have different vascular topology). In the attack scenario, a jailbroken iPhone or compromised Face ID firmware extracts raw IR reflection data (normally processed in the Secure Enclave and discarded) during routine phone unlock. The target never knows their vascular biometric has been captured. Every phone unlock becomes a silent biometric scan. This is analogous to fingerprinting (unreplaceable biometric) but captured at range and without the target's awareness. Combined with QIF-T0078 (pulse waveform), the same IR system yields both vascular structure and cardiac dynamics.

Technique Details

Tactic
QIF-S.HV
Status
EMERGING
Bands
S1, S2, S3

Therapeutic Application

Face ID IR dot projector (940nm) captures subsurface vascular topology via differential hemoglobin absorption; raw IR data extracted from compromised Secure Enclave pipeline

Clinical Analog

Near-infrared spectroscopy (NIRS) for cerebral and peripheral vascular imaging

Treats

  • peripheral artery disease screening
  • diabetic vascular assessment
  • tissue oxygenation monitoring (wound care)
  • cerebral hemodynamics (fNIRS)

Neural Impact

3 of 7 neural bands affected

S1 S2 S3

Drag to rotate. Click a region to learn more.

Click or hover over a glowing region to see the attack techniques targeting it and their severity.

Scoring

NISS v1.1 NISS:1.1/BI:N/CR:N/CD:N/CV:I/RV:F/NP:N
CVSS v4.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
2.0Low
BICRCDCVRVNP
 

Governance

Neurorights at Risk

This technique threatens 2 of the 4 proposed neurorights (Ienca & Andorno, 2017).

Consent Complexity
0.48 / 4.0

FDORA §3305 Compliance

Cyber Device
Regulatory Coverage
0.4 / 1.0
524B Requirements
TM VA SBOM SA PM
Regulatory Gaps
  • ! CVSS partially captures risk; neural dimensions missing
  • ! No FDA pathway for consumer sensor exploitation

Population Vulnerability

CRB vulnerability adjustment (γ=0.30) accounts for age, diagnosis severity, consent capacity, and device dependency.

Population NISS Base Adjusted Severity Delta
Adult (Default) 2.0 2.0 Low -
Child (10yr) + ADHD 2.0 2.4 Low +0.35
Adult with ALS 2.0 2.3 Low +0.32

Validation Status

Theoretical / Not yet validated. This technique has not been independently tested. See the validation dashboard for what has been tested.

Qinnovate Neural Security Atlas Edit this on GitHub