Blog | G5 Cyber Security

Meet WiFiDemon: iOS WiFi RCE 0-Day Vulnerability & a ‘Zero-Click’ Vulnerability That was Silently Patched

ZecOps Mobile EDR Research team investigated if WiFi format-string bug in wifid was exploited in the wild. WiFi Format Strings seem to be a Remote Code Execution (RCE) when joining a malicious SSID. This WiFi Denial of Service (DoS) bug could permanently disable iPhones WiFi functionality, as well as the Hotspot feature. The vulnerability is still a 0day at the time of writing, July 4th. iOS 14.6 is VULNERABLE when connecting to a specially crafted SSID. The fix is taking the following steps according to Forbes.”]

Source: https://blog.zecops.com/research/meet-wifidemon-ios-wifi-rce-0-day-vulnerability-and-a-zero-click-vulnerability-that-was-silently-patched/

Exit mobile version