Skip to main content

A recent HomeKit bug reportedly allowed hackers to unlock your smart door

The problem with smart homes? They are just not all that loyal. A recent HomeKit bug would have allowed just about anyone to take control of the “brain” of one of your connected devices, rendering your smart home … smart on someone else’s behalf. The bug was initially reported by 9to5Mac on Thursday, December 7, and it affected iOS 11.2. Apparently, the bug would have allowed hackers to access any connected smart home device and make adjustments at will — you could have had light bulbs flickering on and off, thermostats set to crazy temperatures, or worst of all, locks being tampered with — all digitally.

Luckily, Apple has since addressed the bug with a software update. Initially, the company disabled remote HomeKit access for shared users, which limited functionality, but an update to iOS 11.2 will be coming next week to offer a more permanent fix.

Recommended Videos

9to5Mac noted that the vulnerability was indeed “difficult to reproduce,” but it did allow “unauthorized control of HomeKit-connected accessories including smart lights, thermostats, and plugs.” And of course, the most concerning aspect was the possibility of hackers taking control of smart locks, garage door openers, and other security devices.

The bug only appeared to be active for folks with an iPhone or iPad on iOS 11.2, the most recent version of Apple’s mobile operating system. Earlier iOS versions appeared to be unaffected by the bug.

Apple was reportedly informed about this alarming vulnerability late in October, but did not completely fix all the issues when the latest operating systems were released. But now, Apple seems to be taking the problem to heart.

The company shared a statement regarding the vulnerability, noting simply, “The issue affecting HomeKit users running iOS 11.2 has been fixed. The fix temporarily disables remote access to shared users, which will be restored in a software update early next week.”

While this bug is clearly concerning, 9to5Mac notes that bugs are a reality in software. But as long as companies take action immediately and responsibly, there shouldn’t be any lingering concerns. After all, hasn’t your life gotten so much better now that you can control everything without getting off your couch?

Lulu Chang
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
6 things you didn’t know Apple Homekit could do
Apple HomeKit app on smartphone.

"Hey, Siri" is a phrase we have all come to know, whether from using it in our daily lives or via a parody of voice assistants. Siri has some great features that we may not utilize daily, one of which is controlling our smart home via HomeKit.

HomeKit is Apple's version of its underlying smart home tech, similar to Google's Home and Assistant and Amazon's Alexa. While HomeKit may not have as many features or accessories as Google Home or Amazon Alexa, there are some fantastic ways to use HomeKit that you may not be using now.

Read more
Are smart lights bulbs worth it?
The Harth Sleep-Shift Light Bulb running next to a bed.

Smart light bulbs are among the most popular smart home devices of 2023. Offering heaps of functionality and clocking in at prices under $30, they’re an affordable way to bring smarts into your home.

But are they actually worth the investment? After all, they’re more expensive than traditional light bulbs -- and unless they do something really special, they may not be worth the hassle.

Read more
Aqara launches U100 smart lock with full Apple HomeKit support
A person unlocking the Aqara U100 smart lock with their phone.

The list of smart locks that support Apple HomeKit isn’t quite as impressive as those of Google Home and Alexa, but Aqara has officially added one more to the list with the Aqara Smart Lock U100. Clocking in at $190 and now available on Amazon, the premium smart lock offers full support for Apple HomeKit -- along with tons of cool features that should position it as a top option for smart home enthusiasts.

As you’d expect, the Aqara U100 comes with a keypad that lets you enter a passcode to unlock the deadbolt. However, you’ll also find a fingerprint scanner that can hold up to 50 unique prints and the option to set up Apple home keys to unlock it with your Apple Watch or iPhone. Aqara also tossed in a physical key in case of emergencies.

Read more