Daily Mail PH

Friday, November 3, 2023

[New post] New vulnerability in iOS 17 enables Bluetooth attacks

Site logo image John Biggs posted: " A new vulnerability has been discovered in iPhones that have been updated to iOS 17, making them susceptible to a Bluetooth attack. This attack, executed using a device known as Flipper Zero, can cause the phone to crash. The discovery of this vulnerabil" Knapsack

New vulnerability in iOS 17 enables Bluetooth attacks

John Biggs

Nov 3

A new vulnerability has been discovered in iPhones that have been updated to iOS 17, making them susceptible to a Bluetooth attack. This attack, executed using a device known as Flipper Zero, can cause the phone to crash. The discovery of this vulnerability was made by security researcher Jeroen van der Ham, who himself fell victim to the exploit while on a train journey.

His phone began displaying multiple pop-up windows before eventually rebooting. Upon investigation, van der Ham found that the culprit was another passenger on the train, who was wielding a Flipper Zero device equipped with custom firmware. This device was used to send a barrage of Bluetooth Low Energy (BLE) alerts to nearby iPhones running on iOS 17.

The Flipper Zero is a compact, versatile device, often likened to the Swiss Army knife of antennas. Its innocuous appearance - a small orange and white plastic gadget with a 1.4-inch display - belies its capabilities. It could easily be mistaken for a child's toy. However, this device is a multi-tool for hacking, capable of communicating with sub-1GHz devices such as old garage doors, RFID devices, NFC cards, infrared devices, and, notably, Bluetooth devices.

The potential attacks that can be launched from a Flipper Zero are numerous. TechCrunch reported on these Bluetooth pop-up attacks last month, revealing that they can also affect iPad devices. More worryingly, there is now a special "iOS 17 Lockup Crash" in the custom Flipper Xtreme firmware that can overwhelm an iPhone and cause it to crash. This attack does not affect iPhones running on older iOS versions, such as iOS 16, suggesting that Apple's latest OS update has inadvertently made iPhones more vulnerable to this type of attack. This attack is not exclusive to Apple devices. Android devices and Windows laptops are also susceptible.

BleepingComputer reported last week that Bluetooth spam attacks can be used on Samsung Galaxy phones to generate an endless stream of pop-ups. However, Android users can protect themselves by disabling the nearby share notification, and unlike on iPhones, the attack does not appear to crash Android devices. For iPhone users running iOS 17, the only reliable way to protect against these pop-up and crash attacks is to disable Bluetooth. This might not be a practical solution for those who regularly use an Apple Watch or Bluetooth headphones, but if you find yourself in a location where a Flipper Zero might be in use, it's a precaution worth considering. As of now, Apple's latest iOS 17.1 update has not addressed this issue, leaving users waiting for a fix to protect against these attacks. In the meantime, it's a stark reminder of the importance of vigilance in the digital age. As technology advances, so too do the methods and tools used by those with malicious intent. It's a constant game of cat and mouse, with security researchers and tech companies working tirelessly to stay one step ahead.


Manage your email settings or unsubscribe.

Trouble clicking? Copy and paste this URL into your browser:
https://knapsacknews.com/new-vulnerability-in-ios-17-enables-bluetooth-attacks/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at November 03, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

CG BOSS Quick check — should I keep you on this list?

You subscribed to CGBOSS in the past and Thank you  ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏...

  • [New post] Achieve Data Sovereignty through Omnisphere
    Crypto Breaking News posted: "Web 3.0 is one of the biggest buzzwords flying around the world of social media this year. An...
  • [New post] Tuesday’s politics thread is trying to stay positive.
    SheleetaHam posted: " Even though I just finished the latest Opening Arguments podcast about how Roe v. Wade is toast, and ...
  • How can the Rappler app be better? We'd like to know what you think!
    Hi daily! Have you downloaded the Rappler app? We'd love to hear about ...

Search This Blog

  • Home

About Me

Daily Newsletters PH
View my complete profile

Report Abuse

Labels

  • Last Minute Online News

Blog Archive

  • February 2026 (1)
  • January 2026 (7)
  • December 2025 (8)
  • November 2025 (4)
  • October 2025 (2)
  • September 2025 (1)
  • August 2025 (2)
  • July 2025 (5)
  • June 2025 (3)
  • May 2025 (2)
  • April 2025 (2)
  • February 2025 (2)
  • December 2024 (1)
  • October 2024 (2)
  • September 2024 (1459)
  • August 2024 (1360)
  • July 2024 (1614)
  • June 2024 (1394)
  • May 2024 (1376)
  • April 2024 (1440)
  • March 2024 (1688)
  • February 2024 (2833)
  • January 2024 (3130)
  • December 2023 (3057)
  • November 2023 (2826)
  • October 2023 (2228)
  • September 2023 (2118)
  • August 2023 (2611)
  • July 2023 (2736)
  • June 2023 (2844)
  • May 2023 (2749)
  • April 2023 (2407)
  • March 2023 (2810)
  • February 2023 (2508)
  • January 2023 (3052)
  • December 2022 (2844)
  • November 2022 (2673)
  • October 2022 (2196)
  • September 2022 (1973)
  • August 2022 (2306)
  • July 2022 (2294)
  • June 2022 (2363)
  • May 2022 (2299)
  • April 2022 (2233)
  • March 2022 (1993)
  • February 2022 (1358)
  • January 2022 (1323)
  • December 2021 (2064)
  • November 2021 (3141)
  • October 2021 (3240)
  • September 2021 (3135)
  • August 2021 (1782)
  • May 2021 (136)
  • April 2021 (294)
Simple theme. Powered by Blogger.