Apple Says 'KRACK' Wi-Fi Vulnerabilities Are Already Patched in iOS, macOS, watchOS, and tvOS Betas

Apple has already patched serious vulnerabilities in the WPA2 Wi-Fi standard that protects many modern Wi-Fi networks, the company told iMore's Rene Ritchie this morning.

The exploits have been addressed in the iOS, tvOS, watchOS, and macOS betas that are currently available to developers and will be rolling out to consumers soon.

A KRACK attack proof-of-concept from security researcher Mathy Vanhoef

Disclosed just this morning by researcher Mathy Vanhoef, the WPA2 vulnerabilities affect millions of routers, smartphones, PCs, and other devices, including Apple's Macs, iPhones, and iPads.

Using a key reinstallation attack, or "KRACK," attackers can exploit weaknesses in the WPA2 protocol to decrypt network traffic to sniff out credit card numbers, usernames, passwords, photos, and other sensitive information. With certain network configurations, attackers can also inject data into the network, remotely installing malware and other malicious software.

Because these vulnerabilities affect all devices that use WPA2, this is a serious problem that device manufacturers need to address immediately. Apple is often quick to fix major security exploits, so it is not a surprise that the company has already addressed this particular issue.

Websites that use HTTPS offer an extra layer of security, but an improperly configured site can be exploited to drop HTTPS encryption, so Vanhoef warns that this is not a reliable protection.

Apple's iOS devices (and Windows machines) are not as vulnerable as Macs or devices running Linux or Android because the vulnerability relies on a flaw that allows what's supposed to be a single-use encryption key to be resent and reused more than once, something the iOS operating system does not allow, but there's still a partial vulnerability.

Once patched, devices running iOS, macOS, tvOS, and watchOS will not be able to be exploited using the KRACK method even when connected to a router or access point that is still vulnerable. Still, consumers should watch for firmware updates for all of their devices, including routers.

Ahead of the release of the update that addresses the vulnerabilities, customers who are concerned about attacks should avoid public Wi-Fi networks, use Ethernet where possible, and use a VPN.

Top Rated Comments

bookwormsy Avatar
78 months ago
Are they going to release a security update for devices that can't run iOS 11?
Score: 30 Votes (Like | Disagree)
BittenApple Avatar
78 months ago
What about for 32 bit devices ?
Score: 17 Votes (Like | Disagree)
iapplelove Avatar
78 months ago
This is why I keep my devices updated, its worth dealing with a few bugs.
Score: 15 Votes (Like | Disagree)
lkrupp Avatar
78 months ago
The computer industry as a whole needs to do a much better job at security. They need to get it right the first time. Not rely on endless patching. Why? Because there are products out there that might not ever be updated, that a manufacturer has already moved on from. Old TV sets, old phones and operating systems that cannot be upgraded, smoke detectors, door locks, light bulbs, refrigerators,...wifi is used in just about everything now.

Got to get this stuff right to begin with. Too important not to.
Yeah, well Wi-Fi has been around for over ten years now and this flaw has just now been discovered. There is literally NO WAY to “get this stuff right to begin with.” Like I have posted once before I worked for AT&T for 34 years in a telephone central office. Digital telephone switches began to be installed in the 1980s and thirty years later those switches are still being patched almost daily. Software development just doesn’t work the way you are expecting it too. There has never been a piece of software released that didn’t require updating or patching. And there never will be.
Score: 12 Votes (Like | Disagree)
QCassidy352 Avatar
78 months ago
Support for 32-bit has ended. The newest 32-bit device was released in 2013. Sorry, but supporting devices that are over 4 years old just doesn't make sense.

Apple supports their devices FAR LONGER than the industry average. If you're concerned, it might be time to consider upgrading to something a bit newer.
That's a very dismissive attitude. So if my 87 year old grandma is perfectly happy with her iPhone 5, she should be forced to buy a new one so as to have access to a software security patch? And if a few hundred bucks is not in her budget as a retired person then "tough luck, hope you don't get hacked"? Apple is one of the biggest and wealthiest companies in the world. I think they can and should see their way clear to coding a security update for 32 bit devices.

And yes, I do acknowledge that support must be cut off at *some* point. I don't expect a patch for the original iPhone on iOS 3. But I don't think it's unreasonable to expect a patch for A6-based devices, which were sold *new* as late as fall 2015.

This is entirely why I’ve always told people “even if you don’t give a damn another the new features, just update to the newest os as long as your device supports it”. But did anyone listen? No. They just sit back all stubborn until something terrible happens
It's weighing the possibility of something terrible happening against the certainty of subsequent updates slowing my device to a frustrating crawl (see: A5 devices on iOS 9). Not a choice I believe we should have to make. They release security updates for older macOS versions and should do the same for iOS, in my opinion.
Score: 12 Votes (Like | Disagree)
Dwalls90 Avatar
78 months ago
That’s great. But still, Apple needs to change the WiFi toggle behavior in control center for these kinds of things.
Sorry but that is a complete separate complaint.
Score: 10 Votes (Like | Disagree)

Popular Stories

iphone se 4 modified flag edges

iPhone SE 4 Details: Action Button, USB-C Port, Face ID, and More

Wednesday September 27, 2023 1:34 pm PDT by
Significant changes are expected to arrive with Apple's fourth-generation iPhone SE, in terms of both design and hardware, MacRumors has learned. The iPhone SE 4, known internally under the codename Ghost, is expected to receive a new design derived almost entirely from the base model iPhone 14. According to our sources, the iPhone SE 4 will use a modified version of the iPhone 14 chassis...
Multi Display CarPlay 1

All-New Apple CarPlay Launching Later This Year With These 5 New Features

Friday September 29, 2023 11:29 am PDT by
At WWDC 2022 last year, Apple previewed the next generation of CarPlay, promising deeper integration with vehicle functions like A/C and FM radio, support for multiple displays across the dashboard, personalization options, and more. Apple said the first vehicles with support for the next-generation CarPlay experience would be announced in late 2023, but it has still not shared any additional...
iOS 17

Everything New in iOS 17.1 Beta 1

Wednesday September 27, 2023 1:57 pm PDT by
Just a week after releasing iOS 17, Apple has seeded the first beta of iOS 17.1 to developers. iOS 17.1 adds some features that Apple promised were coming to iOS 17 in the future, plus it refines and improves some existing features. This guide covers everything new in the first iOS 17.1 beta. Apple Music Favorites You can favorite songs, albums, playlists, and artists in the iOS 17.1...
iPhone 15 Pro lineup

iPhone 15 Pro Overheating Concerns Highlighted in Two More Reports

Thursday September 28, 2023 6:25 am PDT by
iPhone 15 Pro and Pro Max overheating concerns continue to make headlines this week, with the topic highlighted by The Wall Street Journal and Bloomberg. Both of the reports document anecdotal complaints from customers, and outline potential causes, but it's unclear how many devices are actually affected. Bloomberg said the overheating could be caused or compounded by the iPhone's setup...
iPhone 15 Pro lineup

Apple to Address iPhone 15 Pro Overheating Issue With iOS 17 Update

Saturday September 30, 2023 9:28 am PDT by
Apple plans to release an iOS 17 update to address a bug that may contribute to the reported iPhone 15 Pro and iPhone 15 Pro Max overheating issue, according to a statement the company shared today with MacRumors and Forbes reporter David Phelan. Apple also says some recent updates to third-party apps have overloaded the system and contributed to the overheating issue. The report notes that...
iPhone 15 USB C Port Keynote

Some USB-C Power Banks Fail to Work With iPhone 15

Thursday September 28, 2023 2:06 pm PDT by
Apple added a USB-C port to the iPhone 15 lineup this year, allowing it to work with USB-C cables, USB-C power banks, and more. It turns out that some USB-C battery packs are not working properly with Apple's iPhone 15, resulting in charging issues. As highlighted on Reddit and the MacRumors forums, not all existing USB-C power banks can be used with the iPhone 15 models, perhaps due to the...
iOS 17

Apple Releases iOS 17.0.2 and iPadOS 17.0.2 for All iPhones and iPads

Tuesday September 26, 2023 12:47 pm PDT by
Apple today released iOS 17.0.2 and iPadOS 17.0.2 updates, with the software coming five days after the releases of iOS 17.0.1 and iPadOS 17.0.1. Today's iOS 17.0.2 and iPadOS 17.0.2 updates arrive as build 21A351 and can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. Note that iOS 17.0.2 was previously made available for iPhone...