Search

WPA2 Wi-Fi Vulnerability to KRACK Attacks Already Patched by Microsoft, Apple; Google Working on Fix

Advertisement
Highlights
  • Almost every Wi-Fi router could get impacted by a new vulnerability flaw
  • Apple and Microsoft said they have already released patches
  • Google said it is working on a fix that it will release soon
WPA2 Wi-Fi Vulnerability to KRACK Attacks Already Patched by Microsoft, Apple; Google Working on Fix

A newly discovered flaw in the widely used Wi-Fi encryption protocol – WPA2 – could leave millions of users vulnerable to attacks, prompting warnings Monday from the US government and security researchers worldwide.

The US government's Computer Emergency Response Team (CERT) issued a security bulletin saying the flaw can open the door to hackers seeking to eavesdrop on or hijack devices using wireless networks.

"Exploitation of these vulnerabilities could allow an attacker to take control of an affected system," said CERT, which is part of the US Department of Homeland Security.

Also seeWi-Fi Devices Vulnerable to KRACK Attacks: Your 10-Point Cheatsheet

The agency's warning came on the heels of research by computer scientists at the Belgian university KU Leuven, who dubbed the flaw KRACK, for Key Reinstallation Attack. The KRACK attacks target Wi-Fi clients using the WPA2 protocol, and affected operating systems include Linux and Android, with version 6.0 and above said to be especially vulnerable. Also affected are Wi-Fi capable devices running Windows, iOS, macOS, and OpenBSD.

Microsoft said it released a patch on October 10 to protect users of Windows devices. "Customers who have Windows Update enabled and applied the security updates, are protected automatically," Microsoft said.

A Google spokesman said, "We're aware of the issue, and we will be patching any affected devices in the coming weeks." The first devices to be patched will be the company’s own Pixel devices, starting with the November 6 Android security update.

Also seeWi-Fi WPA2 Security Vulnerable to KRACK Attacks: Nearly All Wi-Fi Devices on the Planet Vulnerable

As for Apple, the Cupertino giant says the vulnerability has already been patched in the developer betas currently available for iOS, macOS, tvOS, and watchOS. It will be made available in public betas soon.

The Wi-Fi Alliance, an industry group which sets standards for wireless connections, said computer users should not panic.

"There is no evidence that the vulnerability has been exploited maliciously, and Wi-Fi Alliance has taken immediate steps to ensure users can continue to count on Wi-Fi to deliver strong security protections," the group said in a statement.

"Wi-Fi Alliance now requires testing for this vulnerability within our global certification lab network and has provided a vulnerability detection tool for use by any Wi-Fi Alliance member."

According to the news site Ars Technica, the discovery was a closely guarded secret for weeks to allow Wi-Fi systems to develop security patches.

Attackers can exploit the flaw in "to read information that was previously assumed to be safely encrypted," said a blog post by KU Leuven researcher Mathy Vanhoef.

"This can be abused to steal sensitive information such as credit card numbers, passwords, chat messages, emails, photos, and so on. The attack works against all modern protected Wi-Fi networks."

The researcher said the flaw may also allow an attacker "to inject ransomware or other malware into websites."

The KRACK vulnerability allows attackers to circumvent the "key" on a Wi-Fi connection that keeps data private.

The Belgian researchers said in a paper that devices on all operating systems may be vulnerable to KRACK, including 41 percent of Android devices.

'Be afraid'
The newly discovered flaw was serious because of the ubiquity of Wi-Fi and the difficulty in patching millions of wireless systems, according to researchers.

"Wow. Everyone needs to be afraid," said Rob Graham of Errata Security in a blog post.

"It means in practice, attackers can decrypt a lot of Wi-Fi traffic, with varying levels of difficulty depending on your precise network setup."

Alex Hudson, of the British-based digital service firm Iron Group, said the discovery means that "security built into Wi-Fi is likely ineffective, and we should not assume it provides any security."

Hudson said Wi-Fi users who browse the internet should still be safe due to encryption on most websites but that the flaw could affect a number of internet-connected devices.

"Almost certainly there are other problems that will come up, especially privacy issues with cheaper Internet-enabled devices that have poor security," Hudson said in a blog post.

Researchers at Finland-based security firm F-Secure said in a statement the discovery highlights longstanding concerns about Wi-Fi systems' vulnerability.

"The worst part of it is that it's an issue with Wi-Fi protocols, which means it affects practically every single person in the world that uses Wi-Fi networks," F-Secure said in a statement.

The F-Secure researchers said wireless network users can minimise the risks by using virtual private networks, and by updating devices including routers.

Written with inputs from AFP

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 60 Stylus With Built-In Stylus Launched in India at This Price
  2. OnePlus 13T Set to Launch on This Date; Colours, Display Details Revealed
  3. OpenAI Could Soon Enter the Social Media Space to Take on Meta and X
  4. Realme GT 7 Design, Colour Options Revealed Ahead of April 23 Launch
  5. Honor Power With a Massive 8,000mAh Battery Launched
  6. Acer Super ZX, Acer Super ZX Pro Debut in India: See Price, Availability
  7. CMF Buds 2 Full Specifications Revealed Ahead of Launch
  8. Apple Rolls Out iOS 18.5 Public Beta 1 Update With These Changes
  9. Airtel Partners With Blinkit for Quick Deliveries of SIM Cards in India
  10. Realme Narzo 80 Pro 5G, Narzo 80x 5G Now Available for Purchase in India
  1. OpenAI Reportedly Working on an AI-Powered Social Media Platform
  2. Honor Power With Snapdragon 7 Gen 3 SoC, 8,000mAh Battery Launched: Price, Specifications
  3. iOS 18.5 Public Beta 1 for iPhone With Changes to Mail App and AppleCare Page Rolls Out
  4. CMF Buds 2 Full Specifications Confirmed Ahead of Launch; to Offer Hybrid ANC, ChatGPT Support
  5. Solar Storm Possibility Rises After NOAA Predicts Double CME Strike on Earth
  6. All-Female Spaceflight with Katy Perry and Others Came to Earth Successfully
  7. PhonePe UPI Circle Feature With Seamless Payment Authorisation Launched in India
  8. Earth’s Oceans Were Once Green, And Scientists Say They Could Shift Color Again
  9. Vodafone Idea (Vi) Silently Rolls Out Rs. 340 Recharge Plan With 1GB Daily Data, 28-Day Validity
  10. LG Xboom Buds TWS Earphones With Graphene Drivers, Up to 30 Hours Total Battery Life Launched
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »