Categories: NewsTech

This scary exploit gave hackers total remote control of iPhones via Apple’s AWDL protocol

When you think about hackers, you think off sketchy, hooded characters sitting in a far off land, illegally diving into your hard drives and devices, accessing your files, photos, even your webcam—and victims are none the wiser. That’s obviously a dramatisation of the actual process of hacking a device, but a newly-discovered exploit comes pretty close in terms of the gravity of the consequences.

Google Project Zero security researcher Ian Beer has just published a 30,000 word blog post that details a zero-click iOS vulnerability that allowed attackers remote access to victims’ iPhones—allowing hackers total control over their devices, including email, messages, and photos access. The exploit also had the potential to give access to the iPhone’s microphone and camera to malicious parties.

“A wormable radio-proximity exploit which allows me to gain complete control over any iPhone in my vicinity. View all the photos, read all the email, copy all the private messages and monitor everything which happens on there in real-time.”

Beer did note that he has not found any evidence that the vulnerability was “exploited in the wild”, although this doesn’t necessarily mean that it has never happened before. However, the researcher submitted his findings to Apple prior to this, which means that the vulnerability has been patched since sometime before iOS 13.5. In fact, Apple even credited Beer in change logs prior to that, so the Cupertino-based company isn’t denying the existence of the vulnerability.

How it works

Despite the fact that the vulnerability has been patched in newer versions—and most users regularly stay updated, Apple claims—Beer warns that its mere existence should serve as a warning to security specialists and users alike:

“One person, working alone in their bedroom, was able to build a capability which would allow them to seriously compromise iPhone users they’d come into close contact with.”

The researcher also explained how the exploit works. Basically, the issue stems from Appel’s AWDL protocol—which is used by devices to perform peer-to-peer networks. For example, familiar features like AirDrop and Sidecar work by using ADWL. Back in 2018, one of Apple’s beta builds for iOS was released with function name symbols (that normally aren’t made available), and Beer dug into how AWDL’s lack of built-in encryption could be exploited.

Six months (and a couple of thousand words later), Beer shared his findings. He managed to successfully take control of an iPhone 11 Pro in the room next door—and his equipment was made up of a Raspberri Pi and some off-the-shelf WiFi adapters, along with a MacBook Air. Here’s how it looks:

In any case, you should always keep your devices up to date with OS updates. Putting aside new features and UI tweaks, updates often contain important security patches—such as the zero-click exploit we’re discussing in this article. If you’re keen to read a (very) detailed breakdown of the process, click here for Beer’s blog post.

[ SOURCE , VIA , IMAGE SOURCE ]

Recent Posts

Apple’s Tap to Pay on iPhone is now in Malaysia

First announced in 2022, Apple has finally rolled out Tap to Pay on iPhone in…

3 hours ago

Huawei MatePad Mini: Compact tablet with 8.8″ OLED PaperMatte Display, now available for RM2,199

Huawei has officially launched the MatePad Mini in Malaysia, positioning it as a compact tablet…

4 hours ago

Oppo Find X9 Ultra launched in Malaysia: Quad-Hasselblad camera, industry’s first 50MP 10x telephoto, priced from RM6,799

Oppo has finally and officially pulled the curtain off its latest ultra-flagship smartphone — the…

21 hours ago

ChargEV deploys AC and DC charge points at Sunway Lost World Hotel in Ipoh

ChargEV has a new EV charger location in Ipoh located at Sunway Lost World Hotel…

1 day ago

Tim Cook to step down as Apple CEO after 15 years, John Ternus named successor

Apple has announced a major leadership transition, with Chief Executive Officer (CEO) Tim Cook set…

1 day ago

Zeekr 8X: Premium 900V PHEV SUV, up to triple-motor setup and 0–100km/h in 2.96s

Zeekr has introduced the Zeekr 8X, a new high-performance flagship SUV positioned alongside the Zeekr…

2 days ago

This website uses cookies.