Google's Project Zero uncovers iPhone zero-day Wi-Fi exploit
Buggy code in iOS could have been exploited by hackers to remotely take control of devices
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
iPhone users could have had their devices remotely rebooted and controlled via an iOS exploit, Google's Project Zero has revealed.
The vulnerability was patched by Apple in May, but a variety of iPhones and iOS devices, including the iPhone 11, were susceptible to the vulnerability, according to Project Zero security researcher Ian Beer.
The exploit could have allowed hackers to remotely reboot and take complete control of a device from a distance, enabling them to read emails, messages, download photos and even access the microphone and camera for surveillance purposes.
This was possible because iPhones, iPads, Macs and Apple Watches all use a protocol called Apple Wireless Direct Link (AWDL) to build a mesh network for services such as AirDrop and Sidecar.
Beer came across the exploit while reading through an iOS developer beta in 2018 that had the code for AWDL. Due to the amount of code running on iOS, along with the sheer amount of programmes it runs, Beer suggests that bugs are always "prevalent" and can often be spotted.
It took six months to develop the bug into an exploit and Beer stressed that there is no evidence of it being used in the wild.
"The takeaway from this project should not be: no one will spend six months of their life just to hack my phone, I'm fine," Beer wrote in a blog post.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Instead, it should be: one person, working alone in their bedroom, was able to build a capability which would allow them to seriously compromise iPhone users they'd come into close contact with."
IT Pro has approached Apple for comment, but the iPhone maker patched the vulnerability in March.
The company credited Beer in its changelogs for several of the security updates that are linked to the vulnerability. The tech giant has also pointed out that most iOS users are already using newer versions that have been patched and also suggested that an attacker would need to be in a short range of the Wi-Fi for it to work.
Bobby Hellard is ITPro's Reviews Editor and has worked on CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.
Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.
-
Organizations hit by 90 zero-day vulnerabilities last yearNews Google Threat Intelligence researchers warn that edge devices and security appliances are prime entry points
-
Major data leak forum taken downNews LeakBase enabled the sale and purchase of a huge amount of personal data and had more than 142,000 members
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
Millions of developers could be impacted by flaws in Visual Studio Code extensions – here's what you need to know and how to protect yourselfNews The VS Code vulnerabilities highlight broader IDE security risks, said OX Security
-
CVEs are set to top 50,000 this year, marking a record high – here’s how CISOs and security teams can prepare for a looming onslaughtNews While the CVE figures might be daunting, they won't all be relevant to your organization
-
Microsoft patches six zero-days targeting Windows, Word, and more – here’s what you need to knowNews Patch Tuesday update targets large number of vulnerabilities already being used by attackers
-
Experts welcome EU-led alternative to MITRE's vulnerability tracking schemeNews The EU-led framework will reduce reliance on US-based MITRE vulnerability reporting database
-
Veeam patches Backup & Replication vulnerabilities, urges users to updateNews The vulnerabilities affect Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds – but not previous versions.
-
Two Fortinet vulnerabilities are being exploited in the wild – patch nowNews Arctic Wolf and Rapid7 said security teams should act immediately to mitigate the Fortinet vulnerabilities
-
Everything you need to know about Google and Apple’s emergency zero-day patchesNews A serious zero-day bug was spotted in Chrome systems that impacts Apple users too, forcing both companies to issue emergency patches
