apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
  • iPhone 18
  • iOS 27
  • iPadOS 27
  • macOS
  • MacBook Neo
  • iPhone 17e
  • AirTags
  • iOS 26
  • iPhone 17
  • MacBook Pro
  • iPadOS
  • iMac
  • Mac mini
  • HomePod
  • Apple TV
  • iPad Pro
  • iPhone Air
  • Apple Vision Pro
  • iPhone 16
  • AirPods 4
  • Apple Watch Ultra
  • HomePod Mini
  • MacBook Air
  • iPad
  • AirPods Max
  • AirPods Pro 3
  • Apple Watch Series 3
  • Mac Studio
  • Studio Display
  • iPad Air
  • iPad mini
  • watchOS 27
  • Apple CarPlay
  • Apple Pay
  • watchOS 26
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
apple patient
No Result
View All Result

Kr00k: Security flaw discovered in Wi-Fi encryption

Over a billion devices are affected

Milan Jovicic by Milan Jovicic
27. February 2020 - 17:41 CET
in Apple News
0
Cyber security and digital data protection concept. Icon graphic interface showing secure firewall technology for online data access defense against hackers, viruses and insecure information for privacy.

Cyber security and digital data protection concept. Icon graphic interface showing secure firewall technology for online data access defense against hackers, viruses and insecure information for privacy.

WhatsAppFacebookEmail
Threads

Cyber security researchers today revealed a new hardware vulnerability in widely used Broadcom and Cypress Wi-Fi chips, affecting over a billion devices including smartphones, tablets, laptops, routers and more. 

The security vulnerability, known as "Kr00k" and identified by the identifier CVE-2019-15126, allows attackers to decrypt secure data traffic. The cybercriminal does not even have to be on the same network as his victim - explain security researchers from ESET. "Kr00k" makes it possible to attack devices that use the WPA2-Personal or WPA2-Enterprise protocols with AES-CCMP encryption. This is how a ESET-Researcher:

Our tests confirmed that some client devices from Amazon (Echo, Kindle), Apple (iPhone, iPad, MacBook), Google (Nexus), Samsung (Galaxy), Raspberry (Pi 3), Xiaomi (RedMi), as well as some access points from Asus and Huawei are vulnerable to Kr00k.

What the Kr00k vulnerability makes possible and what it does not

According to security researchers, the Kr00k vulnerability is somewhat reminiscent of the KRACK attacks of 2017, a technique that makes it easier for attackers to hack Wi-Fi passwords protected with the widely used WPA2 network protocol. But there are also differences. The vulnerability itself is not in the encryption protocol but in the WiFi chip. This means that cybercriminals cannot connect to the network directly and launch man-in-the-middle attacks - thus changing the password is also useless. Modern devices that use the WPA3 protocol, the latest WiFi security standard, are not affected according to current knowledge. However, attackers can intercept and decrypt some parts of the secured data traffic. Basically, Kr00k breaks encryption at the wireless level. Therefore, it is important to note that TLS encryption is unaffected. This means that network traffic with websites that use HTTPS is still secure.

How does a “Kr00k” attack work?

When a device is disconnected from wireless network traffic, the WiFi chip deletes the session key in memory and sets it to zero. At the same time, however, the chip also transmits all the data from the buffer that was actually zeroed in an encrypted manner - inadvertently, hence the error. Attackers can then capture data such as DNS, ARP, ICMP, HTTP and more. However, this must be close to the source and go through a series of specific processes. However, this requires advanced knowledge - as ESET explains. According to ESET, such an attack is very complex and cannot be carried out by everyone. But that does not change the severity of the security flaw. 

Can the bug be fixed? Are my iPhone, iPad and Mac also affected?

As already mentioned above, various devices are affected by the vulnerability, including Apple devices. However, manufacturers can take action against "Kr00k" using a software or firmware update. Apple has already taken action in this regard and secured the iPhone, iPad and Mac. Accordingly, there are supposed to be defense mechanisms under iOS 13.2 or iPadOS 13.2 as well as macOS 10.15.1 or newer that can render "Kr00k" harmless. (Photo by World Image / Bigstockphoto)

  • Apple wants to increase Safari's security
  • Mozilla Firefox increases privacy with DoH
Make Apfelpatient a preferred source One click – and you'll see us more often on Google
Was this article helpful?
YesNo
Via: ESET
Tags: iPhonesecurity gap
SendShare17Send
Share

Our Amazon Storefront

A handpicked selection of products for iPhone, Mac and more – sorted by topic and updated regularly.

Shop Now

This post contains affiliate links (including Amazon). We earn a small commission on qualifying purchases – at no extra cost to you. Learn more on our Partner Program page.

Previous Post

Apple submits Powerbeats4 to the FCC

Next Post

Spotify receives iOS update in new design

Milan Jovicic

Milan Jovicic

Milan founded Apfelpatient in 2016 and has been responsible for all editorial content since 2018 — news, rumors, guides, and product reviews. Apple devices here are not test units on loan for two weeks but everyday tools: from the iPhone through MacBook Pro, MacBook Air, and iMac to the Apple Vision Pro, at least one device from nearly every product category is in daily use, many of them replaced annually. Every menu path in a guide is verified on the device before it is published.

Key art for the Apple TV series Pluribus showing a screaming woman against a yellow background, with Pluribus season 2 about to begin filming

Pluribus: Gilligan plans at least three seasons

August 12, 2026 - 8:27 PM CEST
The iPhone 17 lineup in five colors seen from the back, whose successor is expected to adopt the smaller iPhone 18 Dynamic Island from the Pro models

iPhone 18: Smaller Dynamic Island already in the base model

August 12, 2026 - 8:13 PM CEST
Drawn outline of the folded iPhone Ultra with square corners on the hinge side and rounded corners opposite, matching the leaked iPhone Ultra screen protectors

iPhone Ultra: Screen protectors reveal the camera position

August 12, 2026 - 3:58 PM CEST

About APFELPATIENT

APFELPATIENT brings you the latest Apple news, product updates, guides, reviews and tips across the entire Apple ecosystem — from the iPhone to the Mac to the Apple Vision Pro. From the first rumors to confirmed news: researched responsibly.

Follow Apfelpatient

Facebook Instagram YouTube Threads Threads

Company

  • About Apfelpatient
  • Contact
  • Author Profiles

Community

  • Netiquette
  • Push Notifications
  • RSS feed

Legal

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • Cookie Settings
  • Affiliate Program

Resources

  • Sitemap

© 2026 Apfelpatient. All rights reserved.

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights

© 2026 Apfelpatient. All rights reserved. Page Directory

Change language to Deutsch