Security News > 2022 > January > Apple iOS vulnerable to HomeKit 'doorLock' denial of service bug

Apple iOS vulnerable to HomeKit 'doorLock' denial of service bug
2022-01-03 15:39

Apple HomeKit is a software framework that lets iPhone and iPad users control smart home appliances from their devices.

To demonstate the doorLock bug, Spinolas has released a proof-of-concept exploit in the form of an iOS app that has access to Home data and can change HomeKit device names.

Upon attempting to load the large string, a device running a vulnerable iOS version will be thrown into a denial of service state, with a forced reset being the only way out of it.

To make matters worse, once the device reboots and the user signs back into the iCloud account linked to the HomeKit device, the bug will be re-triggered.

"The introduction of a local size limit on the renaming of HomeKit devices was a minor mitigation that ultimately fails to solve the core issue, which is the way that iOS handles the names of HomeKit devices."

As the researcher explains, this attack could be used as a ransomware vector, locking iOS devices into an unusable state and demanding a ransom payment to set the HomeKit device back to a safe string length.


News URL

https://www.bleepingcomputer.com/news/security/apple-ios-vulnerable-to-homekit-doorlock-denial-of-service-bug/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Apple 135 564 4102 1570 2442 8678