A tiny device can be used to put your iPhone, and perhaps Android phones as well, into an endless reboot loop — and while there is a way to mitigate the attack, it's far from ideal.
The device is called Flipper Zero and is typically used for penetration testing, meaning security experts use it to test another device's wireless security. It's not exactly obscure; it can easily be bought online for $169 in the U.S. or €165 in Europe.
Described as a "portable multi-tool for pentesters and geeks in a toy-like body," Flipper Zero can interact with various types of wireless systems, including garage door remotes, TVs, NFC readers, RFID readers, and Bluetooth devices.
The device has been around since 2020 (we actually covered it back then), but Ars Technica and TechCrunch have recently highlighted how Flipper Zero can be used to essentially incapacitate an iPhone by sending an endless flurry of Bluetooth requests. On the victim's iPhone, these could look like a request to connect with a TV, which keep popping up until the phone eventually reboots. This is not a new type of attack, but Flipper Zero is cheap, small, portable, and makes it a lot easier to do.
Security researcher Jeroen van der Ham said he experienced this attack himself. He then set out to replicate it himself in a controlled environment, and he managed to crash an iPhone, though the attack only fully worked on iPhones running iOS 17 or newer.
Here's the problem: You cannot permanently deny these types of request on an iPhone. You can deny the connection, but the requests will keep popping up. The only thing you can really do at this point is to turn Bluetooth off completely, but then your wireless headphones and other Bluetooth accessories will be disconnected from your iPhone, which is hardly ideal. Note that you cannot just switch Bluetooth off in the Control Center; you have to turn Bluetooth off in the phone's Settings to mitigate the attack. Van der Ham says he contacted Apple about the issue but did not hear back from the company.
There are reports saying that Flipper Zero can be used to perform a similar attacks on other devices, such as Android phones and Windows devices, though it's unclear whether it can be used to crash them. Additionally, Android phones do have an option to turn off notifications for Bluetooth connection requests making this a lot less of a nuisance.
Copyright © 2023 Powered by
This $169 device can put your iPhone in a reboot loop. Here's what you can do.-针尖对麦芒网
sitemap
文章
82251
浏览
4323
获赞
44
The Scantron meme is a clever nod to finals week
Scantrons are the bane of any student's existence. But this meme might make them a little less nerveHow to install iOS 18.1 developer beta — try Apple Intelligence now
The iOS 18.1 developer beta is here — and two words explain why this is a big one: Apple IntelEven penguins marched (well, waddled) for science
What's better than clever protest signs? Protest penguins.On Saturday, as thousands of people joinedU.S. Senate introduces AI bill to protect artists and strengthen watermarking
The U.S. Senate has unveiled yet another AI protections bill among a series of similar initiatives,Reddit's former CEO slams Reddit for 'amplifying hate, racism and violence'
On Monday, Reddit CEO Steve Huffman posted an open letter to employees, saying that the company doesThe UK just hit a major renewable energy milestone
For the first time ever, renewables generated more energy than gas and coal combined in the UK. SEEBest laptop deal: Save up to $350 on Lenovo Yoga 7i laptops
SAVE UP TO $350: As of July 26, save up to $350 on various configurations (14-inch and 16-inch) of tAmazon CEO tries to sell kids on working on the moon
Despite all the innovations around us, kids still need as much encouragement as possible to become tThe dark side of college
College-bound vloggers are increasingly uploading "college decision reveal" videos to YouTube. But wFriend is the new AI companion that social media believes is beyond parody
A good AI wearable is hard to come by these days. And as tech startups like HumaneAI and Rabbit R1 aSpaceX will try to achieve 2 impressive feats on Monday
UPDATE: April 30, 2017, 7:21 a.m. EDT SpaceX aborted its launch at the last minute on Sunday due toChina just built the world's biggest floating solar project
China has installed a massive field of solar panels on a particularly poignant site: a lake formed bMeghan and Harry reveal their newborn son's name
The Duke and Duchess of Sussex have announced their newborn son's name: Archie Harrison Mountbatten-We'll always, er, sorta, have the Paris Climate Agreement
The U.S. appears poised to remain in the Paris Climate Agreement in name only, after senior membersRabbit R1 has a major security flaw in its code
"All [Rabbit] R1 responses ever given can be downloaded," according to an R1 research group called R