{"id":51162,"date":"2023-11-03T14:56:19","date_gmt":"2023-11-03T14:56:19","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/11\/03\/this-little-tool-can-crash-an-iphone-running-ios-17\/"},"modified":"2023-11-03T14:56:19","modified_gmt":"2023-11-03T14:56:19","slug":"this-little-tool-can-crash-an-iphone-running-ios-17","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2023\/11\/03\/this-little-tool-can-crash-an-iphone-running-ios-17\/","title":{"rendered":"This little tool can crash an iPhone running iOS 17"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Security researchers have discovered that iPhones updated to iOS 17 are susceptible to a Bluetooth attack using a Flipper Zero device that can crash the phone. <a href=\"https:\/\/arstechnica.com\/security\/2023\/11\/flipper-zero-gadget-that-doses-iphones-takes-once-esoteric-attacks-mainstream\/\" target=\"_blank\" rel=\"noopener\"><em>Ars Technica <\/em>reports<\/a> that security researcher <a href=\"https:\/\/infosec.exchange\/@1sand0s\/111254888425599114\" target=\"_blank\" rel=\"noopener\">Jeroen van der Ham<\/a> fell victim to the exploit on a train journey last month, with his phone displaying multiple pop-up windows before rebooting.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Van der Ham discovered that the attacker, another passenger on the train, was using a Flipper Zero device with custom firmware to send a combination of Bluetooth low energy (BLE) alerts to nearby iPhone handsets running iOS 17.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">The Flipper Zero is a very powerful device that we described as the <a href=\"https:\/\/www.theverge.com\/23433594\/flipper-zero-hacking-gadget-wireless-pentesting-open-source-antenna\" target=\"_blank\" rel=\"noopener\">Swiss Army knife of antennas<\/a> last year. It\u2019s a small orange and white plastic gadget with a 1.4-inch display that looks like it could be a child\u2019s toy. The Flipper Zero is a multi-tool for hacking, as it talks to sub-1GHz devices like old garage doors, RFID devices, NFC cards, infrared devices, and of course, Bluetooth devices.<\/p>\n<\/div>\n<div>\n<div class=\"duet--article--article-pullquote mb-20\">\n<p class=\"duet--article--dangerously-set-cms-markup relative bg-repeating-lines-dark bg-[length:1px_1.2em] pb-8 font-polysans text-28 font-medium leading-120 tracking-1 selection:bg-franklin-20  dark:bg-repeating-lines-light dark:text-white dark:selection:bg-blurple\">There are multiple attacks that can be performed on iPhones from a Flipper Zero<\/p>\n<\/div>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\"><a href=\"https:\/\/techcrunch.com\/2023\/09\/05\/flipper-zero-hacking-iphone-flood-popups\/\" target=\"_blank\" rel=\"noopener\"><em>TechCrunch <\/em>first reported<\/a> on the Bluetooth pop-up attacks last month. These can <a href=\"https:\/\/youtu.be\/OWXt8oTJ1lo\" target=\"_blank\" rel=\"noopener\">also affect iPad<\/a> devices, but it appears there\u2019s now a special \u201ciOS 17 Lockup Crash\u201d in the custom Flipper Xtreme firmware that can actually overwhelm an iPhone and crash it. The attack doesn\u2019t affect iPhones that are running older iOS versions (like iOS 16), so it appears Apple has changed something in its latest OS update to make iPhones susceptible to this form of attack.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">A similar attack can also be used on Android devices and Windows laptops. <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/flipper-zero-can-now-spam-android-windows-users-with-bluetooth-alerts\/\" target=\"_blank\" rel=\"noopener\"><em>BleepingComputer <\/em>reported<\/a> last week that the Bluetooth spam attacks can be used on Samsung Galaxy phones to generate a never-ending amount of pop-ups. You can protect against this on Android by disabling the nearby share notification, and the attack doesn\u2019t appear to crash Android devices.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">If you have an iPhone running iOS 17, then the only reliable way to protect against the pop-ups and crash attack is by disabling Bluetooth. That\u2019s not practical if you use an Apple Watch or Bluetooth headphones regularly, but if you\u2019re in a location where someone might use a Flipper Zero, it\u2019s worth thinking about until Apple is able to update iOS 17 to protect against these attacks. Apple\u2019s latest iOS 17.1 update <a href=\"https:\/\/www.zdnet.com\/article\/ios-17-1-update-still-no-defense-against-flipper-zero-iphone-crashes\/\" target=\"_blank\" rel=\"noopener\">hasn\u2019t fixed the issue<\/a>.<\/p>\n<\/div>\n<div>\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">We\u2019ve reached out to Apple to comment on the Flipper Zero attack, and we\u2019ll update you if the company responds.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.theverge.com\/2023\/11\/3\/23944901\/apple-iphone-ios-17-flipper-zero-attack-bluetooth\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers have discovered that iPhones updated to iOS 17 are susceptible to a Bluetooth attack using a Flipper Zero device that can crash the phone. Ars Technica reports that security researcher Jeroen van der Ham fell victim to the exploit on a train journey last month, with his phone displaying multiple pop-up windows before [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":51163,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-51162","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/51162","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=51162"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/51162\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/51163"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=51162"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=51162"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=51162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}