Skip to main content

Security researchers reveal a flaw that crashes iPhones and iPads over Wi-Fi

ios security flaw reboot cycle iphone cellular signal bars
Greg Mombert/Digital Trends
Security flaws fall on a wide spectrum of severity. On the one end, there are issues that are so exceedingly minor as to hardly warrant any attention, and on the other end, there are flaws that are end-of-the-world, destructive oversights. The iOS flaw uncovered by Skycure researchers Yair Amit and Adi Sharabani, sorry to say, lands in the destructive category.

It has to do with a vulnerability in iOS 8’s handling of secure socket layer (SSL) certificates. As the researchers demonstrated at the RSS Conference in San Francisco this week, certificates manipulated by hackers can lead Internet-connected apps on iPhones and iPads to crash repeatedly, eventually causing the entire operating system to crash. The problem with SSL certificates is coupled with a bug that lets malicious programmers force iOS devices to connect to a Wi-Fi network of their choosing, which makes for a seriously disruptive hack.

Recommended Videos

The researchers call it a “No iOS Zone.” Theoretically, an attacker could create a fake network, automatically capture any iOS device in range, and then release the malformed code, causing some connected iPhones and iPads to endlessly reboot. As long as the worst-affected devices are in range of the signal, the cycle is inescapable — It’s impossible to reach the Wi-Fi settings menu before shutoff begins again.

Please enable Javascript to view this content

In the interest of preventing would-be mischief makers from wreaking havok, Skycure’s withholding the attack’s technical details. In a blog post published Tuesday, the firm says it’s reported the security flaw to Apple, but in the interim, recommends iPhone and iPad users disable Wi-Fi except when absolutely needed. The post also recommends updating to iOS 8.3, which seems to include a few mitigatory measures.

Skycure’s report comes on the heels of a separate disclosure from SourceDNA. The security firm detailed a flaw in 1,500 iOS apps that could be exploited by hackers to steal sensitive information such as credit card numbers and encrypted passwords. Like Skycure, the SourceDNA suggested iPhone, iPad, and Mac users turn off Wi-Fi in public unless necessary.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
5 tablets you should buy instead of the iPad (2022)
The yellow iPad (2022) lying face-down on a green bush.

Apple has finally released two new iPads this calendar year: the iPad Air (2024) and the iPad Pro (2024). However, the regular iPad hasn't been updated since 2022. It's not a bad tablet by any means, but with a little bit of research and know-how, you can find other tablets that might be a much better fit.

Here are the best iPad (2022) alternatives you can purchase now. A few might surprise you.
iPad Air (2024)

Read more
This new Android tablet is everything I wish the 2024 iPad Air was
Vivo Pad 3

China-based Vivo has introduced a new tablet, the Vivo Pad 3, and based on the specs alone, this could fast become one of the best Android tablets of the year. Perhaps more importantly, it could become an exciting competitor to the recently released iPad Air (2024).

The Vivo Pad 3 boasts a 12.1-inch LCD, a 2,800 x 1,968 resolution, and a 7:5 screen ratio. The display, with a P3 gamut, also offers 600 nits peak brightness and HDR10 support. As if that weren't enough, you also get a 144Hz refresh rate.

Read more
Apple’s secret plan to change iPhone batteries forever
Battery inside an iPhone.

In the near future, replacing the battery inside an iPhone won’t be a risk-prone, complex, and messy affair with glue everywhere. According to The Information, Apple is exploring a new technology that will make it easier for people to remove the battery unit inside their iPhones, making replacements and repairs more convenient.

Here’s the detail right from the horse’s mouth: "The new technology—known as electrically induced adhesive debonding—involves encasing the battery in metal, rather than foil as it is currently. That would allow people to dislodge the battery from the chassis by administering a small jolt of electricity to the battery, the people said."

Read more