You’re reading the Apple Newsroom

iOS 17.2 fixes annoying Bluetooth pop-up hack that used Flipper Zero

Omar Moharram
Omar Moharram - Senior Editor
2 Min Read

With iOS 17.2, Apple has seemingly fixed an unharmful yet annoying exploit that allowed actors to remotely surface pop-up notifications on iPhones via a small hobbyist radio device (via ZDNet).

The now-fixed exploit allowed Flipper Zero, a small multipurpose device often used by radio and wireless hobbyists, to remotely send pop-up alerts to every iPhone in its range via Bluetooth. While relatively unharmful, the hack meant that affected iPhones would freeze and become unusable unless restarted, which quickly became annoying.

Flipper Zero cannot natively hack iPhones in this manner. Rather, malicious actors had to install a third-party firmware known as Xtreme that includes an Apple BLE Spam tool which enabled this exploit to take place. Thanks to Flipper Zero’s antenna, this denial-of-service hack could affect all iPhones in a range of 30 feet from the device, the report adds.

ZDNet has performed new tests on iPhones running iOS 17.2 to assess whether the new update fixed the exploit. According to the report, iOS 17.2 significantly reduced the number of Bluetooth pop-ups caused by the hack, even if they still occasionally appear now and then. The never-ending stream of pop-ups is no more, which no longer causes iPhones to crash and freeze requiring a reboot.

The Bluetooth pop-ups resembled those when an iPhone attempts to connect to a nearby Apple device like the AirPods or Apple TV connection prompt. The only way to seemingly bypass this exploit is to completely turn off Bluetooth on your iPhone, with even Lockdown Mode not enough to safeguard your device from this hack.

While Apple hasn’t officially acknowledged that iOS 17.2 fixed the exploit on hand, it seems that the company did take steps to curb its effects.

TOPICS: ,
Share this Article

Editor's Pick

Supercharged is not just another news outlet. We’re a platform on a mission to offer personalized and ad-free news directly to you. Discover more of Supercharged.

You’re reading the Apple Newsroom

  • Loading stock data...

iOS 17.2 fixes annoying Bluetooth pop-up hack that used Flipper Zero

Omar Moharram
Omar Moharram - Senior Editor
2 Min Read

With iOS 17.2, Apple has seemingly fixed an unharmful yet annoying exploit that allowed actors to remotely surface pop-up notifications on iPhones via a small hobbyist radio device (via ZDNet).

The now-fixed exploit allowed Flipper Zero, a small multipurpose device often used by radio and wireless hobbyists, to remotely send pop-up alerts to every iPhone in its range via Bluetooth. While relatively unharmful, the hack meant that affected iPhones would freeze and become unusable unless restarted, which quickly became annoying.

Flipper Zero cannot natively hack iPhones in this manner. Rather, malicious actors had to install a third-party firmware known as Xtreme that includes an Apple BLE Spam tool which enabled this exploit to take place. Thanks to Flipper Zero’s antenna, this denial-of-service hack could affect all iPhones in a range of 30 feet from the device, the report adds.

ZDNet has performed new tests on iPhones running iOS 17.2 to assess whether the new update fixed the exploit. According to the report, iOS 17.2 significantly reduced the number of Bluetooth pop-ups caused by the hack, even if they still occasionally appear now and then. The never-ending stream of pop-ups is no more, which no longer causes iPhones to crash and freeze requiring a reboot.

The Bluetooth pop-ups resembled those when an iPhone attempts to connect to a nearby Apple device like the AirPods or Apple TV connection prompt. The only way to seemingly bypass this exploit is to completely turn off Bluetooth on your iPhone, with even Lockdown Mode not enough to safeguard your device from this hack.

While Apple hasn’t officially acknowledged that iOS 17.2 fixed the exploit on hand, it seems that the company did take steps to curb its effects.

TOPICS: ,
Share this Article
Secured By miniOrange