apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally
No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally
No Result
View All Result
apple patient
No Result
View All Result

AirDrop exploit can reveal emails and phone numbers

by Milan
April 23, 2021
AirDrop exploit

MYKOLAIV, UKRAINE - JULY 10, 2020: Woman using Pinterest app on Iphone 11 at table, closeup

Security researchers have discovered an AirDrop exploit that, under certain circumstances, can share an iPhone user's phone number and email address with strangers.

First of all, the AirDrop exploit allows users to do nothing more than open an iOS or macOS sharing window within a stranger's Wi-Fi range so that they can see their phone number and email address. This means that an AirDrop transfer does not necessarily have to be initiated to be at risk. The security researchers who discovered the vulnerability explain that they reported it to Apple in May 2019. But the company has still not provided a fix for the 1.5 billion affected devices. The problem has already been identified in previous investigations. But in these cases only partial phone numbers could be revealed. In addition, a database was necessary. The latest study, however, states that the full data can now be determined every time someone opens a sharing window, regardless of which option they then select.

AirDrop exploit: Apple uses weak hashing mechanism

Researchers at the Technical University of Darmstadt say the problem is a combination of two aspects. First, in order to offer the "Contacts Only" option for AirDrop, Apple devices must silently request personal data from all devices within range.

Because sensitive data is typically only shared with people the user already knows, AirDrop only displays recipient devices from address book contacts by default. To determine if the other party is a contact, AirDrop uses a mutual authentication mechanism that compares a user's phone number and email address with entries in the other user's address book.

Now to point two. Although the data exchanged is encrypted, Apple uses a relatively weak hashing mechanism.

A team of researchers from the Secure Mobile Networking Lab (SEEMOO) and the Cryptography and Privacy Engineering Group (ENCRYPTO) at TU Darmstadt took a closer look at this mechanism and discovered a serious data protection leak. As an attacker, it is possible to find out the phone numbers and email addresses of AirDrop users - even as a complete stranger. All they need is a WiFi-enabled device and physical proximity to a target that initiates the discovery process by opening the sharing window on an iOS or macOS device. The problems discovered are rooted in Apple's use of hash functions to "obfuscate" the exchanged phone numbers and email addresses during the discovery process. Researchers at TU Darmstadt have already shown that hash functions do not enable data protection-compliant contact discovery, since so-called hash values can be quickly exposed using simple techniques such as brute force attacks.

Apple has not yet responded

Finally, the team explained that it has solved the AirDrop bug with a much more secure approach it calls PrivateDrop. However, despite Apple being made aware of both the privacy issue and a possible solution, Cupertino has not yet fixed the bug. (Photo by New Africa / Bigstockphoto)

  • iOS 14.6 makes it easier to switch between RC & beta versions
Have you already visited our Amazon Storefront? There you'll find a hand-picked selection of various products for your iPhone and other devices – enjoy browsing !
This post contains affiliate links .
Add Apfelpatient to your Google News Feed. 
Was this article helpful?
YesNo
Tags: iOSiPadOSmacOS
Previous Post

iPad Pro 12.9″ with XDR display needs new Magic Keyboard

Next Post

Traveling abroad with AirTags: What you need to know

Next Post
AirTag

Traveling abroad with AirTags: What you need to know

Apple TV+ highlights August 2025

Apple TV+: These are the highlights for August 2025

August 1, 2025
Apple iPhone

Apple sells three billionth iPhone since 2007

August 1, 2025
Apple tariffs

Apple faces record tariff costs in Q4

July 31, 2025

About APFELPATIENT

Welcome to your ultimate source for everything Apple - from the latest hardware like iPhone, iPad, Apple Watch, Mac, AirTags, HomePods, AirPods to the groundbreaking Apple Vision Pro and high-quality accessories. Dive deep into the world of Apple software with the latest updates and features for iOS, iPadOS, tvOS, watchOS, macOS and visionOS. In addition to comprehensive tips and tricks, we offer you the hottest rumors, the latest news and much more to keep you up to date. Selected gaming topics also find their place with us, always with a focus on how they enrich the Apple experience. Your interest in Apple and related technology is served here with plenty of expert knowledge and passion.

Legal

  • Imprint – About APFEPATIENT
  • Cookie Settings
  • Privacy Policy
  • Terms of Use

service

  • Partner Program
  • Netiquette – About APPLEPATIENT

RSS Feed

Follow Apfelpatient:
Facebook Instagram YouTube threads
Apfelpatient Logo

© 2025 Apfelpatient. All rights reserved. | Sitemap

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally

© 2025 Apfelpatient. All rights reserved. | Page Directory