A new persistent denial of service vulnerability named “doorLock” has been discovered in Apple HomeKit, affecting versions from iOS 14.7 to 15.2.

See also: Which Apple products aren't worth their money?
Apple HomeKit is a software framework that allows iPhone and iPad users to control their smart home devices from their phones or tablets.
According to Trevor Spiniolas, the security researcher who publicly disclosed the details, Apple has known about the flaw since August 10, 2021. However, despite repeated promises to fix it, the researcher says that Apple is constantly postponing the security update and the problem remains unresolved.
To enable “doorLock,” an attacker would change the name of the HomeKit device to a string longer than 500,000 characters.
To demonstrate the flaw in DoorLock, Spiniolas released a proof-of-concept exploit in the form of an iOS app that has access to Home data and can change HomeKit device names.
Even if the target user has not added any Home devices to HomeKit, there is still an attack path.
When attempting to load the large string, a device running a vulnerable version of iOS will be thrown into a denial of service (DoS) state, with a forced reset being the only way out. However, resetting the device will result in the removal of all stored data and can only be recovered if you have a backup.
See also: Siri no longer rates Apple Music songs in iOS 15

To make matters worse, once the device is restarted and the user logs back into the iCloud associated with the HomeKit device, the error will be reactivated.
The impact of this attack ranges from having an unusable device that reboots indefinitely to the inability to back up your data from iCloud as reverting to online backup services reactivates the flaw.
As the researcher explains, this attack could be used as a ransomware vector, locking iOS devices into an unusable state and demanding a ransom payment to restore the HomeKit device.
Protection measures
It is important to emphasize that the bug can only be exploited by someone with access to your "Home" or by manually accepting an invitation to it.
This means that there is no reliable method for regaining access to local data after “doorLock” is activated, so users should focus all their efforts on prevention.
Therefore, beware of suspicious invitation messages from email addresses that look like Apple services or HomeKit products.
See also: HomeKit: The “weapon” for secure smart home devices
If the damage is already done, follow these three steps to restore your data from iCloud:
- Restore the affected device from recovery or DFU mode
- Set up the device as usual, but DO NOT sign back into your iCloud account
- After the installation is complete, sign in to iCloud from settings.
- Immediately after this, turn off the switch labeled “Home.” The device and iCloud should now work again without access to Home data.
According to the researcher, Apple's latest estimate for fixing the bug is "early 2022," which will be done via an upcoming security update.
