Um novo bug que afeta chips de Wi-Fi por Broadcom, o fornecedor para iPhones, dispositivos Nexus e Samsung foi descoberto por Zero Projeto do Google. Mais particularmente, researcher Gal Baniamini has provided a detailed analysis on the exploit showing how an attacker could take over a device via Wi-Fi proximity.
Newly Discovered Bug Affects Wi-Fi Chips by Broadcom
For the exploit to take place, no user interaction is required. disse brevemente, if a user and an attacker are sharing the same Wi-Fi network (such as a public hotspot), the user’s device can easily be compromised without their knowledge.
relacionado: Quais são os mais Smartphones seguros em 2017
To demonstrate the attack, the researcher used a Nexus 6P device. It should be noted though that the flaw affects any device running on Broadcom Wi-Fi SoCs, Nexo 5 e 6 inclusivo. Also affected are Samsung flagship devices and all iPhones starting from iPhone 4. Felizmente, the manufacturer has already been informed and collaboration with Google was already initiated so that the bug is fixed.
All the vulnerabilities in the post have been disclosed to Broadcom. Broadcom has been incredibly responsive and helpful, both in fixing the vulnerabilities and making the fixes available to affected vendors, o pesquisador escrevi.
relacionado: Want to Hack an IPhone: Here Is How
Fixes for affected vendors are also in the making.
Apple Has Already Addressed the Issue
The company was quick and has already released a patch addressing the issue. The fix is available in the most recent update – 10.3.1. Escusado será dizer, the update should be installed as soon as possible. Otherwise an attacker within range may be able to execute arbitrary code on the Wi-Fi chip, Apple has explained.
“Broadcom has informed me that newer versions of the SoC utilize the MPU, along with several additional hardware security mechanisms. This is an interesting development and a step in the right direction. They are also considering implementing exploit mitigations in future firmware versions,” the researcher concludes.