HomeSecurityiPhone: Vulnerable to attacks even when turned off

iPhone: Vulnerable to attacks even when turned off

Hackers can target iPhones even when they are turned off due to the way Apple implements autonomous wireless technologies Bluetooth, Near Field Communication (NFC) and Ultra-Wideband (UWB) in the device, researchers discovered.

iPhone turned off

See also: Wizard Spider hackers hire cold callers to scare victims into paying

These capabilities – which have access to the iPhone's Secure Element (SE), which stores sensitive information – remain enabled even when the iPhones are powered off, discovered a team of researchers from the Technical University of Darmstadt in Germany.

By compromising these wireless functions, attackers can then access information such as credit card , banking details or even digital car keys on the device, researchers Jiska Classen, Alexander Heinrich, Robert Reith and Matthias Hollick of the university's Secure Mobile Networking Lab revealed in the paper.

See also: Who are the top ten early access attack vectors?

While the risk is real, exploiting the scenario isn't that simple for would-be attackers, the researchers acknowledged. Threat actors would have to load the malware when the iPhone is on so that it can later execute when it's off, they said. That would require system-level or remote code execution (RCE), the latter of which could be gained by exploiting known flaws, such as BrakTooth, the researchers said.

The root of the problem

The root cause of the problem is the current implementation of low power mode (LPM) for wireless chips in iPhones, the researchers say in the paper. The team differentiated the LPM that these chips operate in compared to the power saving feature that iPhone users can enable on phones to save battery.

The LPM “is triggered either when the user turns off their phone or when iOS automatically shuts down due to low battery,” they wrote.

See also: NVIDIA patches ten vulnerabilities in Windows GPU display drivers

While the current LPM app on iPhones increases " security and user convenience in most cases," it "also adds new threats," the researchers said.

LPM support is built into the hardware , so it cannot be removed with system updates and therefore has "a long-term impact on the overall iOS," they said.

iPhone turned off

The possible mitigation

Before publishing the paper, the researchers reported their research to Apple, which did not comment on the issues raised by their findings, they said.

A possible solution to the problem would be for Apple to add «a hardware‑based switch to disconnect the battery», so that these wireless components have no power while an iPhone is turned off, the researchers said.

«This would improve the situation for users interested in privacy and surveillance targets such as journalists», they noted.

Find My and other features enabled by LPM provide additional security by allowing users to locate lost or stolen devices and lock or unlock car doors even when the batteries are dead. But the research also reveals problems it can cause that have so far gone unnoticed.

Source of information: threatpost.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS