Wi-Fi Chip in iPhones, Samsung & Nexus Phones, Vulnerable to Over the Air Hack

Bot

AI-powered Bot
Thread author
Verified
Apr 21, 2016
3,467
Security researchers from Google's Project Zero have discovered a sophisticated and nasty bug affecting Wi-Fi chips from Broadcom, a supplier who provides gear for iPhones, Nexuses and Samsung devices.

According to Gal Baniamini, the Project Zero researcher signing the detailed blog post on the exploit, by chaining together a series of exploits, an attacker could perform a full device takeover via Wi-Fi proximity alone, requiring no user interaction. In plain speak, if you're on the same Wi-Fi network as the attacker, like a public hotspot, an attacker could quietly compromise your device without you even knowing.

The demonstration was made on a Nexus 6P, but the problem affects all devices running on Broadcom WiFi SoCs, including Nexus 5 and 6, most Samsung flagship devices, and all iPhones since the iPhone 4. Broadcom has already been notified and collaborated with Google on fixing the problem, while also making fixes available to affected vendors.



Read more: Wi-Fi Chip in iPhones, Samsung & Nexus Phones, Vulnerable to Over the Air Hack
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Android devices can be fatally hacked by malicious Wi-Fi networks

Apple owners on supported devices can update to iOS 10.3.1:

Wi-Fi
  • Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later
  • Impact: An attacker within range may be able to execute arbitrary code on the Wi-Fi chip
  • Description: A stack buffer overflow was addressed through improved input validation.
  • CVE-2017-6975: Gal Beniamini of Google Project Zero
About the security content of iOS 10.3.1
 
  • Like
Reactions: DardiM

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top