Latest iOS 9.1 security flaw – allow user to update status on Facebook even if device is locked

Bug in iOS 9.1 which allows any user to update status on Facebook even if their device is locked. What is required on the device? Siri should be enabled Obviously, user should be signin into Facebook (Settings > Facebook) How can users replicate this bug on their devices? Start Siri and ask to update status on Facebook. Siri will ask for the message “you can ask siri to post anything“. Siri will then prompt for confirmation with a message (Post or Cancel). Tap on Post or tell Siri to Post. Siri will update this message to the Facebook even if...