Researchers find a scary data vulnerability in Apple’s AirDrop

Digital Trends

Hackers can tap into AirDrop data and pull your phone number or your email address. This issue has been known since 2019 and has yet to be patched or acknowledged by Apple, though it impacts almost 1.5 billion Apple devices today.

According to a report from security researchers at Germany’s Technical University of Darmstadt, the core of this issue is the way in which AirDrop shares files between Apple devices using the address book and contacts list as an option by default. Per the researchers, since AirDrop leverages “a mutual authentication mechanism,” to compare phone numbers, as well as email addresses, a hacker can easily intercept this information using “a Wi-Fi-capable device” that is nearby to an Apple user sharing through MacOS, iOS, or iPadOS via AirDrop. A proof of concept attack can be found on GitHub.

Recommended Videos

This can be done even if the hacker isn’t in the user’s address book or contacts list. It happens both ways, via Sender Leakage, as well as Receiver Leakage, according to the researchers.

Apple does try to protect the exchanged phone numbers and email addresses via “obfuscating,” but security researchers have found that it does not prevent the reversing of hash values. These can be “quickly reserved,” according to security researchers, through brute force attacks.

The researchers at the Technical University of Darmstadt have developed “PrivateDrop” which can replace AirDrop’s flawed design. This solution is reportedly based on optimized cryptographic private set intersection protocols.

This means it can complete exchanges between certain devices without exchanging the hash values that could otherwise be interpreted. This all can occur with a delay time of around a second. This project is available on GitHub, for those interested in the research behind what went into developing it.

Since Apple hasn’t yet officially released a fix, you can try to avoid using or completely turn off AirDrop if you are concerned. To do this on an iPhone or an iPad, click Settings > General. From there, tap AirDrop > Receiving Off. On MacOS, you can turn off AirDrop by clicking to the Control Center next to the date and time, choosing AirDrop, and then toggling the switch to Off. Additional details are available via Apple if you wish to learn more about AirDrop on MacOS.

Editors' Recommendations

Arif Bacchus is a native New Yorker and a fan of all things technology. Arif works as a freelance writer at Digital Trends…
Are you having iPhone alarm problems? A fix is coming soon

If you’ve slept through an important meeting or missed your alarm lately, it may not be entirely your fault if you’re an iPhone user. For weeks now, iPhone users have been reporting on social media that their devices are no longer ringing.

Today, The Wall Street Journal’s Joanna Stern finally confirmed this. According to Stern, Apple has confirmed that it’s aware of the issue causing some alarms not to play a sound and is working on a fix.
iPhone alarm issues explained
The iPhone alarm problem seems to be tied to Apple’s Attention Aware features. For those unfamiliar, it’s a feature that lowers the volume sound of your alerts and alarms if you’re looking at your device and avoids dimming the screen, similar to how Samsung phones keep the screen on if they see you looking at your screen.

Read more
This one Apple Fitness feature completely changed how I exercise

I have a confession to make: I'm not good at sticking to a workout routine. I love running, high-intensity interval training (HIIT), strength training, etc. In the moment of those exercises and in the post-workout euphoria, I feel amazing. But when it comes to waking up early in the morning to do these things before work? Well, that's where I really struggle.

This has been a problem for a while now. I go to bed with the goal of waking up early and going to the gym, but as I groggily open my eyes to snooze the alarm on my iPhone 15 Pro Max, I end up falling back asleep. And I've been repeating this over and over and over again.

Read more
AirTags range: here’s how far the tracker can reach

Apple AirTags are a helpful tool for tracking valuable possessions like wallets, keys, luggage, and backpacks. These tags employ various technologies that allow you to track your items from short and long distances using your compatible Apple device, such as an iPhone 15 Plus. You might wonder how far you can track your items with AirTags. It's time to find out.
AirTags range, explained

The range of AirTags varies depending on the method you use to locate them. A Bluetooth connection will work when your AirTags are close to your supported Apple device. Otherwise, Apple's Find My network is utilized. Luckily, you don't have to choose the method because it's selected behind the scenes automatically.

Read more