Home > Cyber News > iPhone Wi-Fi Bug Can Disable Its Ability to Connect to Wireless Networks
CYBER NEWS

iPhone Wi-Fi Bug Can Disable Its Ability to Connect to Wireless Networks

iPhone Wi-Fi Bug Can Disable Its Ability to Connect to Wireless Networks-sensorstechforum-comApple’s iOS is prone to a wireless networking naming issue that can disable an iPhone’s ability to connect to a Wi-Fi network.

Discovered by senior security engineer at Ant Financial Light-Year Security Labs Carl Schou, the bug can permanently disable iPhone’s Wi-Fi functionality after joining a network called “%p%s%s%s%s%n”. The feature stays disabled even after rebooting the device or changing the network’s name.




This weird vulnerability can lead to various implications, as threat actors could exploit it to plant suspicious Wi-Fi hotspots with the “%p%s%s%s%s%n” name to damage the iPhone’s wireless features.

Where does the “%p%s%s%s%s%n” Wi-Fi issue come from?

The issue originates from a string formatting bug in the way iOS parses the SSID input, creating a denial-of-service condition. According to a short technical analysis, “to trigger this bug, you need to connect to that WiFi, where the SSID is visible to the victim. A phishing Wi-Fi portal page might as well be more effective.”

Does the “%p%s%s%s%s%n” Wi-Fi bug affect Android devices?

So far, it seems that the problem can’t be re-created on Android devices. As for iPhones that have been affected, their owners should reset their iOS network settings by going to Settings > General > Reset > Reset Network Settings and confirming the action.

In March, security researchers discovered that Automatic Call Recorder, an iOS call recording application contained a bug that could give access to users’ conversations. The only thing needed to exploit the bug is providing the correct phone number. The vulnerability was reported by security researcher Anand Prakash, and is already fixed. The app itself is quite popular among iPhone users, ranked at number 15 in the Apple store’s Business category. Its popularity and widespread use could make the bug’s impact significant.

Shortly said, this bug could enable threat actors to eavesdrop on users’ call recordings from app’s the cloud storage bucket. An unauthenticated API endpoint leaked the cloud storage URL.

Milena Dimitrova

An inspired writer and content manager who has been with SensorsTechForum since the project started. A professional with 10+ years of experience in creating engaging content. Focused on user privacy and malware development, she strongly believes in a world where cybersecurity plays a central role. If common sense makes no sense, she will be there to take notes. Those notes may later turn into articles! Follow Milena @Milenyim

More Posts

Follow Me:
Twitter

Leave a Comment

Your email address will not be published. Required fields are marked *

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...