iOS Wi-Fi Exploit Could Have Let Hackers Remotely Access Nearby iPhones
Earlier this year, Apple patched an iOS vulnerability that potentially could have allowed hackers to remotely access a nearby iPhone and gain control of the entire device.
Devised by Ian Beer, a researcher at Project Zero, Google's vulnerability research team, the exploit used a vulnerability in Apple Wireless Direct Link (AWDL), Apple's proprietary mesh networking protocol that enables features like AirDrop and Sidecar to work.
Beer revealed the stunning exploit on Tuesday in a 30,000-word blog post, which shows in detail how a memory corruption bug in AWDL could give attackers remote access to a user's personal data, including emails, photos, messages, and passwords and crypto keys stored in the keychain.
The vulnerability was discovered by Beer in a 2018 iOS beta that Apple accidentally shipped without stripping function name symbols from the kernelcache, offering a wealth of missing context about how bits of code fit together.
After lengthy investigative work, Beer was able to find code related to AWDL, identify the vulnerability, and target it remotely using a laptop, a Raspberry Pi 4B and a couple of Wi-Fi adapters.
It took six months for Beer to develop the exploit, but by the time he was finished he was able to hack any iPhone that was in radio proximity, run arbitrary code on it, and steal all the user data.
Beer says he has no evidence that the issues he uncovered were exploited in the wild, but "we do know that exploit vendors seem to take notice of these fixes."
The takeaway from this project should not be: no one will spend six months of their life just to hack my phone, I'm fine.
Instead, it should be: one person, working alone in their bedroom, was able to build a capability which would allow them to seriously compromise iPhone users they'd come into close contact with.
Imagine the sense of power an attacker with such a capability must feel. As we all pour more and more of our souls into these devices, an attacker can gain a treasure trove of information on an unsuspecting target.
Apple patched the vulnerability in May with the release of iOS 12.4.7 and iOS 13.3.1, and actually cites Beer in changelogs for several security updates. Apple said that the vast majority of users are already on newer versions of iOS that have been patched.