Security researchers at SkyCure stumbled onto an iOS vulnerability that, at its extreme, may cause all phones (and, presumably iPads) on an attacking network to go into an infinite restart mode. The solution is to either disable WiFi or leave the range of the offending network. As far as I can tell, the harm of this vulnerability is that it disables your phone. There does not appear to be any permanent damage or loss of data.
This is not quite “the sky is falling”, but it is an issue that needs to be addressed. I can only imagine that Apple is busy working on a fix as we speak.
If you are interested in details, the SkyCure researcher who discovered this issue wrote up a pretty interesting blog post that tells the story of his discovery and lays out some (but not all) of the details.
Good thing Android just got a similar bug as well – http://arstechnica.com/security/2015/04/wi-fi-software-security-bug-could-leave-android-windows-linux-open-to-attack/ – we can have Android free zones too.
Fascinating. From the very end of that post: “A patch for the bug has been posted, and, based on Google’s involvement, it will likely be part of an Android security update shortly. However, the distribution of that fix will depend on Android handset manufacturers and carriers to reach end users.”
This is the flaw in the Android distribution model. The Android team has no way to push the fix to all users who want it. The handset manufacturers stand in the way.
Yhe funny thing is, for all who complain about Apple’s “closed system” – Apple actually has and had the ‘muscle’ to make the carriers do it Apple’s way. Google has no such muscle or, it would seem, any interest in supporting its “product”. Carriers prob like Google more, since the carriers can get away with their Stalinist tactics. I hear Samsung does push out updates.
I never connect to wifi that I don’t know and or trust, ever. I’ll use my cellular connection.
As far as “which automatically captures any iOS device in range and gets it to join a fake network” is concerned I presume you have to to have ask to join networks enabled? How can any device “get” iOS to join a fake network?