iPhone Vulnerability Could Have Provided Remote Access Over Wi-Fi: Details

Apple patched a serious vulnerability earlier this year that could have allowed attackers to gain complete control over any iPhone using Wi-Fi. The vulnerability. that has been fixed since the release of iOS 13.5 in May, was initially reported by a researcher of Google’s Project Zero team. It was also noticed by other security researchers. The security flaw existed due to a bug in the iOS kernel that allowed bad actors to gain remote access, without requiring any direct interaction from users.
Known as an unauthenticated kernel memory corruption vulnerability, the issue was reported by Ian Beer of Project Zero. Beer published a 30,000-word blog to detail the vulnerability and provided a proof-of-concept exploit that he built after spending six months.
Although the security researcher developed multiple exploits to understand the flaw, the most advanced one he built was the wormable radio-proximity exploit that allowed him to gain complete control over his iPhone 11 Pro. He was able to deploy the exploit using a laptop, a Raspberry Pi, and some off-the-shelf Wi-Fi adapters.
“View all the photos, read all the email, copy all the private messages and monitor everything which happens on there in real-time,” he said in the post while detailing the scope of the vulnerability.
Beer exploited the buffer overflow bug that existed in a driver for AWDL, which is an Apple-native mesh networking protocol used for enabling features including AirDrop and AirPlay. It had the possibility to give complete access remotely to attackers since the said driver — just like other drivers — exist in the kernel.
“AWDL can be remotely enabled on a locked device using the same attack, as long as it’s been unlocked at least once after the phone is powered on. The vulnerability is also wormable; a device which has been successfully exploited could then itself be used to exploit further devices it comes into contact with,” the researcher wrote.


