Now-Fixed WiFi Vulnerability Left Apple Devices Open to Attack - MacRumors
Skip to Content

Now-Fixed WiFi Vulnerability Left Apple Devices Open to Attack

A vulnerability in WiFi chips made by Cypress Semiconductor and Broadcom left billions of devices susceptible to an attack that allowed nearby attackers to decrypt sensitive data sent over the air.

ipad iphone duo ios 12
The security flaw was detailed at the RSA security conference today (via Ars Technica), and for Apple users, the issue was addressed in the iOS 13.2 and macOS 10.15.1 updates that were released back in late October.

Dubbed Kr00k, the WiFi chip flaw caused vulnerable devices to use an all-zero encryption key to encrypt part of a user's communications. When applied successfully, the attack let hackers decrypt some wireless network packets sent by a vulnerable device. As described by Ars Technica:

Kr00k exploits a weakness that occurs when wireless devices disassociate from a wireless access point. If either the end-user device or the access point is vulnerable, it will put any unsent data frames into a transmit buffer and then send them over the air. Rather than encrypt this data with the session key negotiated earlier and used during the normal connection, vulnerable devices use a key consisting of all zeros, a move that makes decryption trivial.

Chips from Broadcom and Cypress are used in many modern WiFi devices like smartphones, laptops, Internet of Things products, WiFi access points, and routers.

Our tests confirmed that prior to patching, some client devices by Amazon (Echo, Kindle), Apple (iPhone, iPad, MacBook), Google (Nexus), Samsung (Galaxy), Raspberry (Pi 3), Xiaomi (RedMi), as well as some access points by Asus and Huawei, were vulnerable to KrØØk. This totaled to over a billion Wi-Fi-capable devices and access points, at a conservative estimate. Further, many other vendors whose products we did not test also use the affected chipsets in their devices.

According to ESET Research, which published details on the vulnerability, it was disclosed to Broadcom and Cypress along with potentially affected parties. At this time, patches for devices from most major manufacturers have been released.

ESET Research recommends making sure all of the latest updates have been applied to WiFi capable devices to patch the vulnerability.

Popular Stories

Prime Big Deal Days 25 Red and Green

Amazon Launches Prime Day Discounts on AirPods, iPad, MacBook Air, and More

Sunday October 4, 2026 9:15 am PDT by
Earlier this week, we began tracking early Prime Day deals on Apple-related accessories, and now Amazon has introduced major early deals on Apple products as well. This includes AirPods, iPads, MacBooks, and more, all available at some of the lowest prices of the year so far. Note: MacRumors is an affiliate partner with Amazon. When you click a link and make a purchase, we may receive a small...
MagSafe 3 Cable Midnight Feature

Apple Releases MagSafe 3 Charging Cable Firmware Update

Monday October 5, 2026 5:59 am PDT by
For the first time since February 2023, Apple has released a firmware update for the MagSafe 3 charging cable for the MacBook Pro and MacBook Air. Specifically, Apple last week released firmware version 3.2.0 for the USB-C to MagSafe 3 Cable. The previous firmware version for the cable was 3.1.12. It is unclear what is included in the latest firmware, as Apple does not publish release...
Apple Event Logo

Apple Event Reportedly Planned for October 13

Sunday October 4, 2026 5:07 pm PDT by
Last week, Bloomberg's Mark Gurman reported that Apple plans to unveil an all-new smart home hub, a new HomePod mini, and a new Apple TV 4K on Tuesday, October 13. In his Power On newsletter today, Gurman specified that "Apple is planning to hold an event" that...

Top Rated Comments

86 months ago
but we were assured that iOS devices were secure...
Score: 5 Votes (Like | Disagree)
86 months ago
Anybody know if it's fixed in Mojave 10.14.6 ?
Score: 5 Votes (Like | Disagree)
cmaier Avatar
86 months ago

They are as secure as anything else. But Apple designs some of their chips, they don't make them. Contractors do. So the vulnerabilities can still be introduced into the supply chain through the same vector; chip providers... just like the vulnerabilities can be introduced by Apple themselves... or the chip makers suppliers... or...

Most of this stuff is scarier in theory than in practice.
It would be very unlikely for a vulnerability that does not exist in the design to exist in the manufactured silicon. When we design chips, and have them made, we test them extremely thoroughly to make sure they behave identically to the RTL and simulated netlist.

And since the manufacturer does not have a simulate-able netlist, it would be very difficult to introduce intentional flaws while still maintaining full functionality so as to fool this testing.
Score: 4 Votes (Like | Disagree)
86 months ago

Anybody know if it's fixed in Mojave 10.14.6 ?
it's not there, no problem with Mojave and WiFi..

why the angry faces? Apple hasn’t confirmed it, so there’s no problem..
Score: 4 Votes (Like | Disagree)
allpar Avatar
86 months ago

this is why you keep your devices updated because of security risks - most people forget that
Yeah, well, if they make new versions compatible with old software, I can do that, but I'm not spending ten grand to move to Catalina.
Score: 3 Votes (Like | Disagree)
cmaier Avatar
86 months ago

but we were assured that iOS devices were secure...
They are as secure as anything else. This problem was caused by the chip providers (who provide the same chips to everyone else).

This is why Apple needs to continue along the path of making as many of the chips it uses itself.
Score: 3 Votes (Like | Disagree)
Latest Stories
Apple to Report Q4 2026 Earnings on November 2
Apple to Report Q4 2026 Earnings on November 2
4 minutes ago
Three Years of 80% Charge Limits on iPhone: The Results
Three Years of 80% Charge Limits on iPhone: The Results
2 hours ago
macOS 27.2 Further Hints at MacBook With Touch-Enabled OLED Display
macOS 27.2 Further Hints at MacBook With Touch-Enabled OLED Display
3 hours ago
The 15 Best Apple Deals Under $200 for Prime Day
The 15 Best Apple Deals Under $200 for Prime Day
4 hours ago
AirPods Pro 3 and AirPods Max 2 Get Big Price Drops for Prime Day
AirPods Pro 3 and AirPods Max 2 Get Big Price Drops for Prime Day
4 hours ago
Apple Releases Second Public Betas of iOS 27.2 and macOS Golden Gate 27.2
Apple Releases Second Public Betas of iOS 27.2 and macOS Golden Gate 27.2
5 hours ago
'Crossy Road Rush' Launching Exclusively on Apple Arcade in November
'Crossy Road Rush' Launching Exclusively on Apple Arcade in November
5 hours ago
Apple Watch Series 9 vs. Series 12 Buyer's Guide: Is It Worth Upgrading?
Apple Watch Series 9 vs. Series 12 Buyer's Guide: Is It Worth Upgrading?
6 hours ago
Prime Day Savings: TVs, Headphones, Chargers, and Other Tech Accessories
Prime Day Savings: TVs, Headphones, Chargers, and Other Tech Accessories
6 hours ago
Apple TV 4K Rumored to Support Four HomePods for Surround Sound
Apple TV 4K Rumored to Support Four HomePods for Surround Sound
7 hours ago
iPhone 18 Pro and Duo Were Once Planned With 16GB RAM, Leaker Says
iPhone 18 Pro and Duo Were Once Planned With 16GB RAM, Leaker Says
7 hours ago
Apple's Entire Mac Lineup Gets Massive Discounts for Prime Day
Apple's Entire Mac Lineup Gets Massive Discounts for Prime Day
8 hours ago
Prime Day iPad Deals Include Low Prices on iPad Air, iPad Mini, and More
Prime Day iPad Deals Include Low Prices on iPad Air, iPad Mini, and More
8 hours ago
Apple's $634 Million Apple Watch Patent Bill Just Got Even Bigger
Apple's $634 Million Apple Watch Patent Bill Just Got Even Bigger
9 hours ago
Amazon Prime Big Deal Days Offers Major Discounts on AirPods, iPads, and Much More
Amazon Prime Big Deal Days Offers Major Discounts on AirPods, iPads, and Much More
4 hours ago
Microsoft OneDrive to Drop Support for These iPhone Models
Microsoft OneDrive to Drop Support for These iPhone Models
10 hours ago
HomePod Mini Waits Reach Eight Weeks Ahead of Rumored Refresh
HomePod Mini Waits Reach Eight Weeks Ahead of Rumored Refresh
10 hours ago
Apple Music Is Getting a New Logo
Apple Music Is Getting a New Logo
11 hours ago
Apple Quietly Boosts Email Feature for iCloud+ Subscribers
Apple Quietly Boosts Email Feature for iCloud+ Subscribers
11 hours ago
iOS 27.2 May Let You Hide Specific Suggested Actions in Messages
iOS 27.2 May Let You Hide Specific Suggested Actions in Messages
12 hours ago
Sources: Apple Planning Two Sets of Product Launches in October
Sources: Apple Planning Two Sets of Product Launches in October
19 hours ago
Apple Announces iPhone Duo Apps Can Now Be Submitted to App Store
Apple Announces iPhone Duo Apps Can Now Be Submitted to App Store
20 hours ago
macOS 27.2 Adds Touch Gestures Ahead of MacBook Ultra
macOS 27.2 Adds Touch Gestures Ahead of MacBook Ultra
1 day ago
Apple and AT&T Have Yet to Explain Cause of iPhone 18 Pro Max Issue
Apple and AT&T Have Yet to Explain Cause of iPhone 18 Pro Max Issue
1 day ago
tvOS 27.2 Code Hints at Apple Intelligence for New Apple TV
tvOS 27.2 Code Hints at Apple Intelligence for New Apple TV
1 day ago
Apple Seeds Third macOS Golden Gate 27.2 Beta to Developers
Apple Seeds Third macOS Golden Gate 27.2 Beta to Developers
1 day ago
Apple Releases Third watchOS 27.2, tvOS 27.2 and visionOS 27.2 Betas
Apple Releases Third watchOS 27.2, tvOS 27.2 and visionOS 27.2 Betas
1 day ago
Apple Releases Third iOS 27.2 Beta
Apple Releases Third iOS 27.2 Beta
1 day ago
Apple Cash Adds ID Check for Reloads, Teases Bank Funding
Apple Cash Adds ID Check for Reloads, Teases Bank Funding
1 day ago
Apple Configurator App Updated
Apple Configurator App Updated
1 day ago