
Security Expert from Google Project Zero Ian Bir found a vulnerability into iOS, which allows you to grab control over the device at a distance. He described the details on his blog.
In the BIR scheme, the vulnerability of the patented Apple AWDL protocol was used, with the help of which, in particular, the Airdrop function used to transmit photos works. At the same time, the expert managed to make AWDL turn on even on the iPhones on which he was disabled earlier.
In order for the iPhone to be available for hacking, its owner only had to connect to the same WiFi network as the attacker. Bir has created several ways to operate vulnerability - in particular, with one of the attacks, he was able to access all the user's personal data, including passwords saved in the phone.
Bir spent about six months to work on the search and use of vulnerabilities.
“The conclusion from this should not be from the series“ No one will spend six months of his life to hack my phone, everything is fine. ” On the contrary, he should be like this: one person, working in his bedroom, was able to create a program that allows you to seriously compromise users of iPhones who have come into contact with him, ”the security specialist emphasized.
Vulnerability was fixed with the update of iOS 13.5, published in May 2020. Bir emphasized that he did not know anything that she could ever be used by hackers. Apple was not recognized, but they did not deny the presence of vulnerability.
Grigory Levchenko