iOS Wi-Fi Exploit Could Have Let Hackers Remotely Access Nearby iPhones

Earlier this year, Apple patched an iOS vulnerability that potentially could have allowed hackers to remotely access a nearby iPhone and gain control of the entire device.

awdl ios hack beer
Devised by Ian Beer, a researcher at Project Zero, Google's vulnerability research team, the exploit used a vulnerability in Apple Wireless Direct Link (AWDL), Apple's proprietary mesh networking protocol that enables features like AirDrop and Sidecar to work.

Beer revealed the stunning exploit on Tuesday in a 30,000-word blog post, which shows in detail how a memory corruption bug in AWDL could give attackers remote access to a user's personal data, including emails, photos, messages, and passwords and crypto keys stored in the keychain.

The vulnerability was discovered by Beer in a 2018 iOS beta that Apple accidentally shipped without stripping function name symbols from the kernelcache, offering a wealth of missing context about how bits of code fit together.

After lengthy investigative work, Beer was able to find code related to AWDL, identify the vulnerability, and target it remotely using a laptop, a Raspberry Pi 4B and a couple of Wi-Fi adapters.

It took six months for Beer to develop the exploit, but by the time he was finished he was able to hack any ‌iPhone‌ that was in radio proximity, run arbitrary code on it, and steal all the user data.

Beer says he has no evidence that the issues he uncovered were exploited in the wild, but "we do know that exploit vendors seem to take notice of these fixes."

The takeaway from this project should not be: no one will spend six months of their life just to hack my phone, I'm fine.

Instead, it should be: one person, working alone in their bedroom, was able to build a capability which would allow them to seriously compromise iPhone users they'd come into close contact with.

Imagine the sense of power an attacker with such a capability must feel. As we all pour more and more of our souls into these devices, an attacker can gain a treasure trove of information on an unsuspecting target.

Apple patched the vulnerability in May with the release of iOS 12.4.7 and iOS 13.3.1, and actually cites Beer in changelogs for several security updates. Apple said that the vast majority of users are already on newer versions of iOS that have been patched.

Tag: Exploit

Top Rated Comments

haruhiko Avatar
45 months ago
For the people who never updates their phones, please take note.
Score: 31 Votes (Like | Disagree)
kstotlani Avatar
45 months ago

At least 99% of the iPhone users can update to the latest version with all the critical fixes if they want. Most Android users have to get a new phone to get the latest OS updates.
There was an interesting conversation between Joe Rogan and Snowden. Snowden mentioned that Android’s fragmentation makes it difficult for hackers because there are so many versions across thousands of different devices. It’s hard to concentrate and develop exploits for such variety. Hackers would rather concentrate on devices like iPhones where there is likelihood of more devices with the same version of the OS. Makes sense doesn’t it?
Score: 12 Votes (Like | Disagree)
Mettwurst Avatar
45 months ago
"Even faster on the new Apple M1 Macbook Air"
Score: 10 Votes (Like | Disagree)
m.x Avatar
45 months ago

This was fixed in iOS 12.4.7. The latest iOS 12 version is iOS 12.4.9. It can be installed on an iPhone 5s, iPhone 6, and iPhone 6+. All later phones, starting with iPhone 6s, can run iOS 13 and iOS 14, which also fix the problem.
Simply using iOS 13 does not fix the problem - he demonstrates the attack using an iPhone 11 Pro on iOS 13.2. You need iOS 13.3.1 as it was patched there. It‘s a bit nitpicky but this information is missing in the Macrumors article as someone might think „oh, I’m running iOS 13.1 so I’m not affected“.
Score: 7 Votes (Like | Disagree)
0815 Avatar
45 months ago
At least 99% of the iPhone users can update to the latest version with all the critical fixes if they want. Most Android users have to get a new phone to get the latest OS updates.
Score: 7 Votes (Like | Disagree)
vionc Avatar
45 months ago
That is really impressive. Kudos to Ian Beer!
Score: 5 Votes (Like | Disagree)

Popular Stories

iOS 18 Siri Integrated Feature

iOS 18 Rumored to Add These 10 New Features to Your iPhone

Wednesday April 24, 2024 2:05 pm PDT by
Apple is set to unveil iOS 18 during its WWDC keynote on June 10, so the software update is a little over six weeks away from being announced. Below, we recap rumored features and changes planned for the iPhone with iOS 18. iOS 18 will reportedly be the "biggest" update in the iPhone's history, with new ChatGPT-inspired generative AI features, a more customizable Home Screen, and much more....
Apple Silicon AI Optimized Feature Siri

Apple Releases Open Source AI Models That Run On-Device

Wednesday April 24, 2024 3:39 pm PDT by
Apple today released several open source large language models (LLMs) that are designed to run on-device rather than through cloud servers. Called OpenELM (Open-source Efficient Language Models), the LLMs are available on the Hugging Face Hub, a community for sharing AI code. As outlined in a white paper [PDF], there are eight total OpenELM models, four of which were pre-trained using the...
maxresdefault

Apple Announces 'Let Loose' Event on May 7 Amid Rumors of New iPads

Tuesday April 23, 2024 7:11 am PDT by
Apple has announced it will be holding a special event on Tuesday, May 7 at 7 a.m. Pacific Time (10 a.m. Eastern Time), with a live stream to be available on Apple.com and on YouTube as usual. The event invitation has a tagline of "Let Loose" and shows an artistic render of an Apple Pencil, suggesting that iPads will be a focus of the event. Subscribe to the MacRumors YouTube channel for more ...
macbook pro purple february

Best Buy Introduces Record Low Prices on Apple's M3 MacBook Pro for Members

Thursday April 25, 2024 7:41 am PDT by
Best Buy is discounting a collection of M3 MacBook Pro computers today, this time focusing on the 14-inch version of the laptop. Every deal in this sale requires you to have a My Best Buy Plus or Total membership, although non-members can still get solid second-best prices on these MacBook Pro models. Note: MacRumors is an affiliate partner with Best Buy. When you click a link and make a...
apple id account

Apple ID Accounts Logging Out Users and Requiring Password Reset

Saturday April 27, 2024 12:41 am PDT by
There are widespread reports of Apple users being locked out of their Apple ID overnight for no apparent reason, requiring a password reset before they can log in again. Users say the sudden inexplicable Apple ID sign-out is occurring across multiple devices. When they attempt to sign in again they are locked out of their account and asked to reset their password in order to regain access. ...
macos sonoma feature purple green

Apple's Regular Mac Base RAM Boosts Ended When Tim Cook Took Over

Friday April 26, 2024 6:34 am PDT by
Apple used to regularly increase the base memory of its Macs up until 2011, the same year Tim Cook was appointed CEO, charts posted on Mastodon by David Schaub show. Earlier this year, Schaub generated two charts: One showing the base memory capacities of Apple's all-in-one Macs from 1984 onwards, and a second depicting Apple's consumer laptop base RAM from 1999 onwards. Both charts were...