iPhone Flaw Let Malware Run Even When Device Is Turned Off

Share post:

Researchers at Germany’s Technical University of Darmstadt have discovered a vulnerability in the Bluetooth chip of the iPhone. The flaw allows attackers to run malicious firmware on an iPhone device even when the device is turned off.

The malware allows attackers to track the location of the phone or perform new functions even when the device is off.

Research helps to unravel the dangers of the low power mode (LPM) that gives room for the flaw on Apple iPhones. When an iPhone is turned off, it is not shut down completely, but the device runs in a low-power mode, which allows it to perform some actions, including locating the device if it is lost.

“The current LPM implementation on Apple iPhones is opaque and adds new threats. Since LPM support is based on the iPhone’s hardware, it cannot be removed with system updates. Thus, it has a long-lasting effect on the overall iOS security model. To the best of our knowledge, we are the first who looked into undocumented LPM features introduced in iOS 15 and uncover various issues.,” the researchers’ paper states.

While the always-on feature on the iPhone offers immense usage, it can also be exploited by hackers. Aside from allowing malware to run while the iPhone is turned on, exploits targeting LPM could also enable malware to operate with much more stealth, since LPM allows firmware to save battery power.

The sources for this piece include an article in ArsTechnica.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways