apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally
No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally
No Result
View All Result
apple patient
No Result
View All Result

Kr00k: Security flaw discovered in Wi-Fi encryption

Over a billion devices are affected

by Milan
February 27, 2020
Cyber security and digital data protection concept. Icon graphic interface showing secure firewall technology for online data access defense against hackers, viruses and insecure information for privacy.

Cyber security and digital data protection concept. Icon graphic interface showing secure firewall technology for online data access defense against hackers, viruses and insecure information for privacy.

Cyber security researchers today revealed a new hardware vulnerability in widely used Broadcom and Cypress Wi-Fi chips, affecting over a billion devices including smartphones, tablets, laptops, routers and more. 

The security vulnerability, known as "Kr00k" and identified by the identifier CVE-2019-15126, allows attackers to decrypt secure data traffic. The cybercriminal does not even have to be on the same network as his victim - explain security researchers from ESET. "Kr00k" makes it possible to attack devices that use the WPA2-Personal or WPA2-Enterprise protocols with AES-CCMP encryption. This is how a ESET-Researcher:

Our tests confirmed that some client devices from Amazon (Echo, Kindle), Apple (iPhone, iPad, MacBook), Google (Nexus), Samsung (Galaxy), Raspberry (Pi 3), Xiaomi (RedMi), as well as some access points from Asus and Huawei are vulnerable to Kr00k.

What the Kr00k vulnerability makes possible and what it does not

According to security researchers, the Kr00k vulnerability is somewhat reminiscent of the KRACK attacks of 2017, a technique that makes it easier for attackers to hack Wi-Fi passwords protected with the widely used WPA2 network protocol. But there are also differences. The vulnerability itself is not in the encryption protocol but in the WiFi chip. This means that cybercriminals cannot connect to the network directly and launch man-in-the-middle attacks - thus changing the password is also useless. Modern devices that use the WPA3 protocol, the latest WiFi security standard, are not affected according to current knowledge. However, attackers can intercept and decrypt some parts of the secured data traffic. Basically, Kr00k breaks encryption at the wireless level. Therefore, it is important to note that TLS encryption is unaffected. This means that network traffic with websites that use HTTPS is still secure.

How does a “Kr00k” attack work?

When a device is disconnected from wireless network traffic, the WiFi chip deletes the session key in memory and sets it to zero. At the same time, however, the chip also transmits all the data from the buffer that was actually zeroed in an encrypted manner - inadvertently, hence the error. Attackers can then capture data such as DNS, ARP, ICMP, HTTP and more. However, this must be close to the source and go through a series of specific processes. However, this requires advanced knowledge - as ESET explains. According to ESET, such an attack is very complex and cannot be carried out by everyone. But that does not change the severity of the security flaw. 

Can the bug be fixed? Are my iPhone, iPad and Mac also affected?

As already mentioned above, various devices are affected by the vulnerability, including Apple devices. However, manufacturers can take action against "Kr00k" using a software or firmware update. Apple has already taken action in this regard and secured the iPhone, iPad and Mac. Accordingly, there are supposed to be defense mechanisms under iOS 13.2 or iPadOS 13.2 as well as macOS 10.15.1 or newer that can render "Kr00k" harmless. (Photo by World Image / Bigstockphoto)

  • Apple wants to increase Safari's security
  • Mozilla Firefox increases privacy with DoH
Add Apfelpatient to your Google News Feed. 
Was this article helpful?
YesNo
Via: ESET
Tags: iPhonesecurity gap
Previous Post

Apple submits Powerbeats4 to the FCC

Next Post

Spotify receives iOS update in new design

Next Post
Anapa, Russia - October 3, 2019: Man holding iPhone 11 with music service Spotify on the screen. iPhone 11 was created and developed by the Apple inc.

Spotify receives iOS update in new design

iPhone 17 Pro Apple

iPhone 17 Pro: These four camera innovations are coming in 2025

July 4, 2025
Apple Smart Glasses

When will Apple launch its own smart glasses?

July 4, 2025
iPhone China

iPhone sales in China are picking up again

July 4, 2025

About APFELPATIENT

Welcome to your ultimate source for everything Apple - from the latest hardware like iPhone, iPad, Apple Watch, Mac, AirTags, HomePods, AirPods to the groundbreaking Apple Vision Pro and high-quality accessories. Dive deep into the world of Apple software with the latest updates and features for iOS, iPadOS, tvOS, watchOS, macOS and visionOS. In addition to comprehensive tips and tricks, we offer you the hottest rumors, the latest news and much more to keep you up to date. Selected gaming topics also find their place with us, always with a focus on how they enrich the Apple experience. Your interest in Apple and related technology is served here with plenty of expert knowledge and passion.

Legal

  • Imprint – About APFEPATIENT
  • Cookie Settings
  • Privacy Policy
  • Terms of Use

service

  • Partner Program
  • Netiquette – About APPLEPATIENT

RSS Feed

Follow Apfelpatient:
Facebook Instagram YouTube threads
Apfelpatient Logo

© 2025 Apfelpatient. All rights reserved. | Sitemap

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Tests & Experience Reports
  • Generally

© 2025 Apfelpatient. All rights reserved. | Page Directory