Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Hackers Exploit Apple’s Wi-Fi System
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Hackers Exploit Apple’s Wi-Fi System

Highlights

  • Researchers found a major vulnerability in Apple’s Wi-Fi Positioning System.

  • An attacker can track Wi-Fi access points globally using BSSIDs.

  • Effective measures are needed to mitigate the identified privacy risks.

Samantha Reed
Last updated: 23 May, 2024 - 12:22 pm 12:22 pm
Samantha Reed 12 months ago
Share
SHARE

Security researchers have unveiled a significant vulnerability in Apple’s Wi-Fi Positioning System (WPS), enabling hackers to globally track the locations of Wi-Fi access points and their owners. This discovery raises serious privacy concerns for users who rely on Apple’s extensive network of devices to determine their geographic location. The research highlights the potential for attackers to build a comprehensive database of Wi-Fi networks and trace device movements over time, even without direct access to GPS data.

Contents
Implications of the VulnerabilityReal-World ImpactKey Recommendations

A study by the University of Maryland researchers has shown that an unprivileged attacker can leverage Apple’s crowdsourced location tracking system to gather data on Wi-Fi access points globally. This can be achieved by querying the WPS with BSSIDs (Basic Service Set Identifiers), which are unique identifiers for Wi-Fi access points. Apple’s system uses data from its large network of iPhones, iPads, and MacBooks, which periodically report the GPS coordinates of nearby Wi-Fi BSSIDs to Apple’s servers. Even without GPS connectivity, Apple devices can estimate their location through visible BSSIDs.

Implications of the Vulnerability

The vulnerability allows attackers to exploit the WPS by querying with BSSIDs derived from the IEEE public database of Organizationally Unique Identifiers (OUIs). This method enables the discovery of millions of Wi-Fi access point locations globally, without prior knowledge. The WPS returns the location of the queried BSSID along with the coordinates of up to 400 nearby access points, broadening the scope of potential tracking.

The researchers collected data over a year, identifying the locations of over 2 billion BSSIDs on every continent. This information can be used to track device movements over time, particularly for mobile devices like travel routers. Such data can reveal sensitive information about users’ location history, posing significant privacy risks. The study emphasizes the need for Wi-Fi access points to regularly randomize their MAC addresses to prevent such tracking.

Real-World Impact

The research team demonstrated the potential real-world impact through various case studies, highlighting significant security concerns. For instance, they tracked troop and refugee movements in conflict zones like Ukraine and Gaza and monitored the aftermath of natural disasters. Additionally, the researchers identified Starlink satellite internet terminals used by the Ukrainian military, illustrating the broad implications of the vulnerability.

Key Recommendations

  • Wi-Fi access points should regularly randomize their MAC addresses to prevent tracking.
  • WPS operators should restrict access to their APIs to limit misuse.
  • Governments should consider regulating the use of WPS data for privacy protection.

The responsible disclosure of the vulnerability prompted Apple and other stakeholders to take action. Apple now allows Wi-Fi access point owners to opt out of location tracking by appending “_nomap” to their SSID. Manufacturers like SpaceX have started deploying firmware updates to randomize device MAC addresses. However, the researchers argue that more comprehensive measures are needed to mitigate the risks effectively.

The discovery underscores the often-overlooked privacy risks associated with geolocation services based on widespread Wi-Fi usage. The findings highlight the necessity for enhanced privacy protections in emerging wireless standards and internet-connected devices. As our infrastructure becomes increasingly connected, identifying and addressing these privacy blind spots is crucial to safeguarding user privacy.

  • Researchers found a major vulnerability in Apple’s Wi-Fi Positioning System.
  • An attacker can track Wi-Fi access points globally using BSSIDs.
  • Effective measures are needed to mitigate the identified privacy risks.
You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

DHS Faces Scrutiny for Withholding CISA Workforce Details

MITRE’s CVE Program Faces Funding Shake-up and Future Alternatives

Microsoft Tackles 72 Vulnerabilities in May Security Update

Apple Boosts Security With Extensive Software Updates

US Authorities Dismantle Botnets and Indict Foreign Nationals

Share This Article
Facebook Twitter Copy Link Print
Samantha Reed
By Samantha Reed
Samantha Reed is a 40-year-old, New York-based technology and popular science editor with a degree in journalism. After beginning her career at various media outlets, her passion and area of expertise led her to a significant position at Newslinker. Specializing in tracking the latest developments in the world of technology and science, Samantha excels at presenting complex subjects in a clear and understandable manner to her readers. Through her work at Newslinker, she enlightens a knowledge-thirsty audience, highlighting the role of technology and science in our lives.
Previous Article Apple’s iPhone 16 Pro Max to Feature New Sensors
Next Article Ecovacs Launches T30 Pro Omni with Advanced Features

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Pushed by Tesla, Panasonic Boosts US Battery Cell Production
Electric Vehicle
Satellite Companies Advance IoT with New Innovations
IoT
Wordle Enthusiasts Crack Today’s Puzzle with Strategic Tips
Gaming
OpenAI Targets UAE for New Data Center
AI Technology
Waymo Recalls 1,200 Robotaxis Over Software Glitch
Robotics
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?