Skip to main content
  1. Home
  2. Phones
  3. Computing
  4. Mobile
  5. News

Project Zero finds large vulnerability involving Broadcom Wi-Fi chips

Add as a preferred source on Google

Google’s Project Zero continues to strap on its cape to make the world a safer place for us to use our electronics, this time helping to discover a dangerous flaw in Broadcom Wi-Fi chips. That hardware can be found in a variety of smartphones, including iPhones, Nexus phones, and a variety of Samsung devices.

Project Zero has been helping to rid the world of exploits and security flaws for a few years now, regularly releasing information on these bugs to manufacturers and then giving them a short time period to correct the problem before it’s made public. In this case, the Project Zero researcher and bug discoverer, Gal Beniamini, said that Broadcam had been very “responsive,” helped fix the bug, and explained its problem to manufacturers.

Recommended Videos

Apple has responded with a security update, fixing up the problem in its 10.3.1 release, though it hasn’t released a comment on the bug. Techcrunch notes that Google has declined to comment on the matter.

It’s good to see speedy responses, though. From the detailed breakdown of the bug, it seems like a nasty one. It uses a series of exploits to breach the Broadcom chip’s security, which can in turn be used to take over the entire device it’s built into. All of that can be achieved wirelessly, with no direct interaction with the handset in question.

Theoretically, anyone on a shared Wi-Fi network, private or public, could compromise a device built with Broadcom’s Wi-Fi system on a chip (SOC).

Fortunately it sounds like Broadcom has been very open to advice on how to improve its security and has now informed Project Zero that newer versions of its Wi-Fi SoC will utilize a memory protection unit and several other hardware security measures. We’re told that these should fix most of the exploit paths used to make this bug viable and Broadcom is also considering implementing “exploit mitigations in future firmware versions,” as well.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
Vivo X300 FE review: The compact flagship I didn’t expect to like this much
The Vivo X300 FE is the Hawkeye of flagships. It doesn't have superpowers, but somehow gets the job done better than everyone else.
Vivo X300 FE

Why Hawkeye?

Hawkeye was never the strongest Avenger, nor did he have the flashiest suit or superpowers. Yet he consistently proved his worth through precision, reliability, and doing the fundamentals exceptionally well. The Vivo X300 FE follows the same philosophy. It doesn't chase outrageous specifications or marketing gimmicks. Instead, it quietly nails the essentials with a superb display, dependable performance, excellent cameras, and outstanding battery life. It may not grab all the headlines, but when it matters, it's the flagship that gets the job done.

Read more
7 Apple Notes tips to elevate your note-taking experience
A few small tweaks buried in the menus that make Apple Notes feel like a completely different app.
Apple notes on iPhone

Over the years, Apple has turned Apple Notes into one of the best note-taking apps for the iPhone. The problem is that most people use the app just as a place to dump info and do not use it to its full potential. Today, I will share seven of my favorite Apple Notes tips that will elevate your note-taking experience. 

Switch between recently opened notes

Read more
This Android lock screen bug lets anyone text using Gemini without knowing your PIN
Google confirms a fix is coming for this risky Gemini lock screen bug
google-gemini

Your Android lock screen is supposed to keep your messages safe, even if someone gets hold of your phone. But a newly discovered Gemini bug could do the opposite. Since May, The Register has received multiple reports of people bypassing device authentication on Android 16 devices that allow Gemini access straight from the lock screen.

The flaw lets anyone use Gemini to send SMS and even WhatsApp messages without ever entering your PIN. It only works under specific conditions, but it is serious enough that Google has confirmed a fix is already rolling out.

Read more