iOS Wi-Fi Exploit Could Have Let Hackers Remotely Access Nearby iPhones

Earlier this year, Apple patched an iOS vulnerability that potentially could have allowed hackers to remotely access a nearby iPhone and gain control of the entire device.

awdl ios hack beer
Devised by Ian Beer, a researcher at Project Zero, Google's vulnerability research team, the exploit used a vulnerability in Apple Wireless Direct Link (AWDL), Apple's proprietary mesh networking protocol that enables features like AirDrop and Sidecar to work.

Beer revealed the stunning exploit on Tuesday in a 30,000-word blog post, which shows in detail how a memory corruption bug in AWDL could give attackers remote access to a user's personal data, including emails, photos, messages, and passwords and crypto keys stored in the keychain.

The vulnerability was discovered by Beer in a 2018 iOS beta that Apple accidentally shipped without stripping function name symbols from the kernelcache, offering a wealth of missing context about how bits of code fit together.

After lengthy investigative work, Beer was able to find code related to AWDL, identify the vulnerability, and target it remotely using a laptop, a Raspberry Pi 4B and a couple of Wi-Fi adapters.

It took six months for Beer to develop the exploit, but by the time he was finished he was able to hack any ‌iPhone‌ that was in radio proximity, run arbitrary code on it, and steal all the user data.

Beer says he has no evidence that the issues he uncovered were exploited in the wild, but "we do know that exploit vendors seem to take notice of these fixes."

The takeaway from this project should not be: no one will spend six months of their life just to hack my phone, I'm fine.

Instead, it should be: one person, working alone in their bedroom, was able to build a capability which would allow them to seriously compromise iPhone users they'd come into close contact with.

Imagine the sense of power an attacker with such a capability must feel. As we all pour more and more of our souls into these devices, an attacker can gain a treasure trove of information on an unsuspecting target.

Apple patched the vulnerability in May with the release of iOS 12.4.7 and iOS 13.3.1, and actually cites Beer in changelogs for several security updates. Apple said that the vast majority of users are already on newer versions of iOS that have been patched.

Tag: Exploit

Popular Stories

Apple iPhone 16e Feature

Apple Announces iPhone 16e With A18 Chip and Apple Intelligence, Pricing Starts at $599

Wednesday February 19, 2025 8:02 am PST by
Apple today introduced the iPhone 16e, its newest entry-level smartphone. The device succeeds the third-generation iPhone SE, which has now been discontinued. The iPhone 16e features a larger 6.1-inch OLED display, up from a 4.7-inch LCD on the iPhone SE. The display has a notch for Face ID, and this means that Apple no longer sells any iPhones with a Touch ID fingerprint button, marking the ...
iphone 17 pro asherdipps

iPhone 17 Pro Models Rumored to Feature Aluminum Frame Instead of Titanium Frame

Tuesday February 18, 2025 12:02 pm PST by
Over the years, Apple has switched from an aluminum frame to a stainless steel frame to a titanium frame for its highest-end iPhones. And now, it has been rumored that Apple will go back to using aluminum for three out of four iPhone 17 models. In an investor note with research firm GF Securities, obtained by MacRumors this week, Apple supply chain analyst Jeff Pu said the iPhone 17, iPhone...
apple launch feb 2025 alt

Here Are the New Apple Products We're Still Expecting This Spring

Thursday February 20, 2025 5:06 am PST by
Now that Apple has announced its new more affordable iPhone 16e, our thoughts turn to what else we are expecting from the company this spring. There are three product categories that we are definitely expecting to get upgraded before spring has ended. Keep reading to learn what they are. If we're lucky, Apple might make a surprise announcement about a completely new product category. M4...
Generic iOS 18

Here's When Apple Will Release iOS 18.4

Wednesday February 19, 2025 11:38 am PST by
Following the launch of the iPhone 16e, Apple updated its iOS 18, iPadOS 18, and macOS Sequoia pages to give a narrower timeline on when the next updates are set to launch. All three pages now state that new Apple Intelligence features and languages will launch in early April, an update from the more broader April timeframe that Apple provided before. The next major point updates will be iOS ...
prioritize notifications ios 18 4

Everything New in iOS 18.4 Beta 1

Friday February 21, 2025 1:08 pm PST by
Apple finally released the first beta of iOS 18.4 to developers for testing purposes, and while the beta is lacking some of the Apple Intelligence features we were hoping for, there are some notable new additions. Subscribe to the MacRumors YouTube channel for more videos. Priority Notifications - Apple Intelligence There is a new Priority Notifications feature that can show you your most...
apple launch feb 2025

Tim Cook Teases an 'Apple Launch' Next Wednesday

Thursday February 13, 2025 8:07 am PST by
In a social media post today, Apple CEO Tim Cook teased an upcoming "launch" of some kind scheduled for Wednesday, February 19. "Get ready to meet the newest member of the family," he said, with an #AppleLaunch hashtag. The post includes a short video with an animated Apple logo inside a circle. Cook did not provide an exact time for the launch, or share any other specific details, so...
iPhone 16e Feature

Apple Denies Speculation Surrounding iPhone 16e's Lack of MagSafe

Friday February 21, 2025 8:01 am PST by
Apple has confirmed that its custom-designed C1 modem in the iPhone 16e has nothing to do with the device's lack of MagSafe support, according to Macworld. Following the launch of the iPhone 16e, there was some speculation online about how MagSafe magnets might have interfered with the C1 modem's cellular connectivity performance, and this was considered to be a potential reason for the...
apple c1

Apple Unveils 'C1' as First Custom Cellular Modem

Wednesday February 19, 2025 8:08 am PST by
Apple today announced its first custom cellular modem with the name "C1," debuting in the all-new iPhone 16e. The new modem contributes to the iPhone 16e's power efficiency, giving it the longest battery life of any iPhone with a 6.1-inch display, such as the iPhone 15 and iPhone 16. Expanding the benefits of Apple silicon, C1 is the first modem designed by Apple and the most...

Top Rated Comments

haruhiko Avatar
55 months ago
For the people who never updates their phones, please take note.
Score: 31 Votes (Like | Disagree)
kstotlani Avatar
55 months ago

At least 99% of the iPhone users can update to the latest version with all the critical fixes if they want. Most Android users have to get a new phone to get the latest OS updates.
There was an interesting conversation between Joe Rogan and Snowden. Snowden mentioned that Android’s fragmentation makes it difficult for hackers because there are so many versions across thousands of different devices. It’s hard to concentrate and develop exploits for such variety. Hackers would rather concentrate on devices like iPhones where there is likelihood of more devices with the same version of the OS. Makes sense doesn’t it?
Score: 12 Votes (Like | Disagree)
Mettwurst Avatar
55 months ago
"Even faster on the new Apple M1 Macbook Air"
Score: 10 Votes (Like | Disagree)
m.x Avatar
55 months ago

This was fixed in iOS 12.4.7. The latest iOS 12 version is iOS 12.4.9. It can be installed on an iPhone 5s, iPhone 6, and iPhone 6+. All later phones, starting with iPhone 6s, can run iOS 13 and iOS 14, which also fix the problem.
Simply using iOS 13 does not fix the problem - he demonstrates the attack using an iPhone 11 Pro on iOS 13.2. You need iOS 13.3.1 as it was patched there. It‘s a bit nitpicky but this information is missing in the Macrumors article as someone might think „oh, I’m running iOS 13.1 so I’m not affected“.
Score: 7 Votes (Like | Disagree)
0815 Avatar
55 months ago
At least 99% of the iPhone users can update to the latest version with all the critical fixes if they want. Most Android users have to get a new phone to get the latest OS updates.
Score: 7 Votes (Like | Disagree)
vionc Avatar
55 months ago
That is really impressive. Kudos to Ian Beer!
Score: 5 Votes (Like | Disagree)