Skip to main content

Security researchers reveal a flaw that crashes iPhones and iPads over Wi-Fi

ios security flaw reboot cycle iphone cellular signal bars
Greg Mombert/Digital Trends
Security flaws fall on a wide spectrum of severity. On the one end, there are issues that are so exceedingly minor as to hardly warrant any attention, and on the other end, there are flaws that are end-of-the-world, destructive oversights. The iOS flaw uncovered by Skycure researchers Yair Amit and Adi Sharabani, sorry to say, lands in the destructive category.

It has to do with a vulnerability in iOS 8’s handling of secure socket layer (SSL) certificates. As the researchers demonstrated at the RSS Conference in San Francisco this week, certificates manipulated by hackers can lead Internet-connected apps on iPhones and iPads to crash repeatedly, eventually causing the entire operating system to crash. The problem with SSL certificates is coupled with a bug that lets malicious programmers force iOS devices to connect to a Wi-Fi network of their choosing, which makes for a seriously disruptive hack.

Recommended Videos

The researchers call it a “No iOS Zone.” Theoretically, an attacker could create a fake network, automatically capture any iOS device in range, and then release the malformed code, causing some connected iPhones and iPads to endlessly reboot. As long as the worst-affected devices are in range of the signal, the cycle is inescapable — It’s impossible to reach the Wi-Fi settings menu before shutoff begins again.

In the interest of preventing would-be mischief makers from wreaking havok, Skycure’s withholding the attack’s technical details. In a blog post published Tuesday, the firm says it’s reported the security flaw to Apple, but in the interim, recommends iPhone and iPad users disable Wi-Fi except when absolutely needed. The post also recommends updating to iOS 8.3, which seems to include a few mitigatory measures.

Skycure’s report comes on the heels of a separate disclosure from SourceDNA. The security firm detailed a flaw in 1,500 iOS apps that could be exploited by hackers to steal sensitive information such as credit card numbers and encrypted passwords. Like Skycure, the SourceDNA suggested iPhone, iPad, and Mac users turn off Wi-Fi in public unless necessary.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
iPadOS 17 just made my favorite iPad feature even better
Stage Manager on iPad Pro with M1

With iPadOS 17, Apple promised a refined Stage Manager experience. So, as soon as the first public beta was released, I rushed to my iPad Pro to check whether Apple’s claims made at WWDC 2023 had any merit to them. Well, Apple delivered with Stage Manager on iPadOS 17 — and to a large extent.

One of my biggest gripes with Stage Manager was that it wasn’t flexible. Apple wanted to ape a core multitasking feature from macOS, but the implementation left a lot to be desired. Digital Trends Editor Joe Manager wrote an extensive (and lukewarm) take on how Stage Manager didn't live up to its promises.

Read more
An iPhone just sold for a crazy amount at auction
An original, unsealed iPhone.

An original, still-boxed iPhone. LCG Auctions

Rare iPhones have been going under the hammer for some large sums in recent months, and the latest auction to feature one of the first Apple handsets has just smashed the record for such a device.

Read more
I ditched my iPad Pro for an Android tablet — here’s why
Man holding green OnePlus Pad Android tablet over space gray 11-inch M1 iPad Pro 2021.

I work from home full time. That means distractions walk in freely, and keeping myself engaged is not always easy. In search of motivation, I lean toward change, novelty, and the urge to avoid being chained to my desk all day.

In this pursuit, the iPad Pro has proven to be a terrific gadget that allows me to get away from the clutter on my desk without giving up the capabilities of a computer. Being a Mac user, the iPad Pro easily fits into my workflow, primarily for seamless Continuity.

Read more