• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Gadgets

Researchers invent iPhone malware that works even if your phone is off

May 17, 2022
Share on FacebookShare on Twitter

What would you do if you discovered malware on your iPhone?

Your first instinct might be to turn the darn thing off to stop malicious snooping. Unfortunately, even that might not be enough.

A new type of malware conceived by researchers at the Technical University of Darmstadt would be able to run even when your phone’s power is off. And no, I’m not talking about an NSA-style fake power-off screen.

“Baloney!” you shout. How can malware run without electricity? The simple answer is that these days, devices are rarely fully “off.”

The research is summarized in the 1-minute video below:

The exploit leverages the iPhone’s Low Power Mode, which is compatible with every iPhone since 2018, starting with the iPhone Xr and Xs. This mode allows the NFC, Ultra-Wideband, and Bluetooth chips to sip a little power when the rest of the phone is off.

Since iOS 15, these chips can run indefinitely, allowing your phone to be localizable via Find My, as well as enabling features like Express Cards and Car Key to remain operational.

That’s obviously really useful if you ever lose your phone, but it opens the potential for a new kind of malware that can run until your battery is absolutely, 100% depleted.

The Bluetooth chip has its own firmware that can run separately from the main processor. This firmware is at the heart of the study; according to the researchers, it is completely unsigned, has “no protection against modification,” and “attackers could run Bluetooth malware even after shutdown.”

The Bluetooth and UWB chips are hardwired to the Secure Element in Apple’s NFC chip, which stores information for Apple Pay, Car Keys, and Express Cards. That essentially means the information stored in the Secure Element can be made accessible by attacking the Bluetooth chip’s firmware.

Worse, “since LPM support is implemented in hardware, it cannot be removed” by system updates. And firmware-level exploits leveraging low power modes could be extremely difficult to detect; malware can sometimes be identified simply because it causes more battery drain.

Before you go and trade your iPhones for a flip phone, it’s worth noting that the exploit detailed in the paper requires a jailbroken iPhone, significantly decreasing the chances regular users will be affected by this exploit. The researchers also shared their findings with Apple, which will likely seek to address these concerns on future devices.

Still, it goes to show that with every convenient new feature, there’s a new opportunity for bad guys to exploit. It is not inconceivable for hackers to find ways to jailbreak iPhones remotely, as happened with Pegasus. For every exploit made public early, there are others we don’t find out about until it’s too late.

The researchers acknowledge that LPM applications are meant to increase security and safety for most users, but say “Apple should add a hardware-based switch to disconnect the battery. Such a change “would improve the situation for privacy-concerned users and surveillance targets like journalists.”

Via Ars Technica

Next Post

Fall Guys is going free to play ahead of Switch, Xbox launch

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Google TV adds new ways to ‘Create’ with your family photos and AI, teases Shorts row
  • YC-backed Skio sold to Recharge for $105M cash after reaching $32M ARR with no marketing or sales team
  • DJI banned in both Beijing and Washington as drone security fears squeeze world’s largest maker from both sides
  • OpenAI adds AI pets to its Codex coding tool
  • Make YouTube Music look good on foldables with this setting

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously