iOS Wi-Fi Exploit Could Have Let Hackers Remotely Access Nearby iPhones

Earlier this year, Apple patched an iOS vulnerability that potentially could have allowed hackers to remotely access a nearby iPhone and gain control of the entire device.

awdl ios hack beer
Devised by Ian Beer, a researcher at Project Zero, Google's vulnerability research team, the exploit used a vulnerability in Apple Wireless Direct Link (AWDL), Apple's proprietary mesh networking protocol that enables features like AirDrop and Sidecar to work.

Beer revealed the stunning exploit on Tuesday in a 30,000-word blog post, which shows in detail how a memory corruption bug in AWDL could give attackers remote access to a user's personal data, including emails, photos, messages, and passwords and crypto keys stored in the keychain.

The vulnerability was discovered by Beer in a 2018 iOS beta that Apple accidentally shipped without stripping function name symbols from the kernelcache, offering a wealth of missing context about how bits of code fit together.

After lengthy investigative work, Beer was able to find code related to AWDL, identify the vulnerability, and target it remotely using a laptop, a Raspberry Pi 4B and a couple of Wi-Fi adapters.

It took six months for Beer to develop the exploit, but by the time he was finished he was able to hack any ‌iPhone‌ that was in radio proximity, run arbitrary code on it, and steal all the user data.

Beer says he has no evidence that the issues he uncovered were exploited in the wild, but "we do know that exploit vendors seem to take notice of these fixes."

The takeaway from this project should not be: no one will spend six months of their life just to hack my phone, I'm fine.

Instead, it should be: one person, working alone in their bedroom, was able to build a capability which would allow them to seriously compromise iPhone users they'd come into close contact with.

Imagine the sense of power an attacker with such a capability must feel. As we all pour more and more of our souls into these devices, an attacker can gain a treasure trove of information on an unsuspecting target.

Apple patched the vulnerability in May with the release of iOS 12.4.7 and iOS 13.3.1, and actually cites Beer in changelogs for several security updates. Apple said that the vast majority of users are already on newer versions of iOS that have been patched.

Tag: Exploit

Popular Stories

Generic iOS 18 Feature Real Mock

iOS 18 Available Today With These 8 New Features For Your iPhone

Sunday September 15, 2024 10:09 am PDT by
Following over three months of beta testing, iOS 18 will finally be widely released to the public this Monday, September 16. The update should be available to install starting at around 10 a.m. Pacific Time (1 p.m. Eastern Time) in the Settings app under General → Software Update on the iPhone XS and newer. Below, we have highlighted eight key new features included in iOS 18, and Apple...
iOS 18 Public Beta Thumb 1

Here's When iOS 18 Rolls Out Today in Every Time Zone

Monday September 16, 2024 3:56 am PDT by
It's that time of year again. Apple is about to release iOS 18, which promises to bring a range of new features and improvements to iPhones worldwide. It's Apple's biggest software update of the year, and the company is expected to release it sometime today – Monday, September 16. Based on past releases, the update is likely to drop at around 10:00 a.m. Pacific Time/1:00 p.m. Eastern...
Beyond iPhone 13 Better Blue Face ID Single Camera Hole

10 Reasons to Wait for Next Year's iPhone 17

Friday September 13, 2024 2:40 am PDT by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models simultaneously, which is why we sometimes get rumored feature leaks so far ahead of launch. The iPhone 17 series is no different – already we have some idea of what to expect from Apple's 2025 smartphone lineup. If you plan to skip...
apple silicon mac lineup wwdc 2022 feature purple

M4 Macs, New iPad Mini, and iPad 11 Expected at Upcoming Apple Event

Sunday September 15, 2024 5:29 am PDT by
Apple will likely hold another event in October this year to announce new Macs and iPads. If so, it would be the fourth time in the last five years that Apple has held an event in October. Last year, Apple held a virtual event on Monday, October 30 to announce new MacBook Pro and iMac models with the M3 series of chips. In his Power On newsletter today, Bloomberg's Mark Gurman reiterated...
16 pro

iPhone 16 Pro Demand Has Been Lower Than Expected, Analyst Says

Sunday September 15, 2024 3:58 pm PDT by
Apple analyst Ming-Chi Kuo today said demand for the iPhone 16 Pro and iPhone 16 Pro Max has been "lower than expected" since the devices became available to pre-order in the U.S. and dozens of other countries on Friday. Kuo said his data is based on a "supply chain survey" and shipping estimates listed on Apple's online store. Kuo estimated that sales of all four iPhone 16 models reached...
iphone 16 pro apple intelligence

Apple Intelligence Features Expected to Roll Out in This Order Between iOS 18.1 and iOS 18.4

Friday September 13, 2024 1:01 pm PDT by
iOS 18 will be released to the public on Monday, but the first Apple Intelligence features will not be available until iOS 18.1 is released in October. Apple Intelligence features will continue to roll out in iOS 18.2 and beyond, with the expected roadmap outlined below per Apple's website and rumors. Apple Intelligence requires an iPhone 15 Pro model or any iPhone 16 model, and it will...

Top Rated Comments

haruhiko Avatar
50 months ago
For the people who never updates their phones, please take note.
Score: 31 Votes (Like | Disagree)
kstotlani Avatar
50 months ago

At least 99% of the iPhone users can update to the latest version with all the critical fixes if they want. Most Android users have to get a new phone to get the latest OS updates.
There was an interesting conversation between Joe Rogan and Snowden. Snowden mentioned that Android’s fragmentation makes it difficult for hackers because there are so many versions across thousands of different devices. It’s hard to concentrate and develop exploits for such variety. Hackers would rather concentrate on devices like iPhones where there is likelihood of more devices with the same version of the OS. Makes sense doesn’t it?
Score: 12 Votes (Like | Disagree)
Mettwurst Avatar
50 months ago
"Even faster on the new Apple M1 Macbook Air"
Score: 10 Votes (Like | Disagree)
m.x Avatar
50 months ago

This was fixed in iOS 12.4.7. The latest iOS 12 version is iOS 12.4.9. It can be installed on an iPhone 5s, iPhone 6, and iPhone 6+. All later phones, starting with iPhone 6s, can run iOS 13 and iOS 14, which also fix the problem.
Simply using iOS 13 does not fix the problem - he demonstrates the attack using an iPhone 11 Pro on iOS 13.2. You need iOS 13.3.1 as it was patched there. It‘s a bit nitpicky but this information is missing in the Macrumors article as someone might think „oh, I’m running iOS 13.1 so I’m not affected“.
Score: 7 Votes (Like | Disagree)
0815 Avatar
50 months ago
At least 99% of the iPhone users can update to the latest version with all the critical fixes if they want. Most Android users have to get a new phone to get the latest OS updates.
Score: 7 Votes (Like | Disagree)
vionc Avatar
50 months ago
That is really impressive. Kudos to Ian Beer!
Score: 5 Votes (Like | Disagree)