1.5 billion Apple devices at risk due to AirDrop vulnerability

There is information that there is a vulnerability in Apple AirDrop that affects about 1.5 billion Apple devices. Earlier this week, researchers from the Technical University of Darmstadt posted on their blog a vulnerability in the AirDrop data transfer technology, which was developed by Apple and first introduced in OS X Lion and iOS 7.

The vulnerability is related to the fact that AirDrop uses a mutual authentication mechanism to compare the user’s phone number and email with the entries in the address book of the device with which he is communicating. Researchers have found that attackers can obtain this data from a Wi-Fi-enabled device and close to the target, initiating the detection process by opening a file sharing panel on an iOS or macOS device. The vulnerability is caused by the way the phone number and email address are hashed during authentication.

1.5 billion Apple devices at risk due to AirDrop vulnerability

The researchers note that they first drew attention to this problem back in 2019 and immediately informed Apple about it. However, the California tech giant has yet to take any action to address the vulnerability.

For users concerned about data leaks, researchers recommend turning off AirDrop completely.

.

You may also like