iPhones reveal your unique MAC despite Apple's promises

Three years ago, Apple added a privacy-enhancing feature that hid the Wi-Fi address of iPhones and iPads when they connected to a .

On Wednesday, the whole world learned that the feature never worked as advertised.

Despite the company's promises that this never-changing address would remain hidden and be replaced with a private one that would be unique to each SSID, Apple devices continued to display the real address to every connected device on the network.private wi-fi address

In 2020, Apple released iOS 14 with a feature that, by default, hid the Wi-Fi address when devices connected to a network. The device displayed what Apple called a “private Wi-Fi address” that was different for each SSID. Over time, Apple has improved the feature, for example by allowing users to assign a new private Wi-Fi address for a given SSID.

On Wednesday, Apple released iOS 17.1. Among the various fixes was one for vulnerability CVE-2023-42846, which prevented this particular privacy feature. Tommy Mysk, one of two security researchers who discovered and reported the vulnerability (Talal Haj Bakry was the other), told Ars that he tested all recent versions of iOS and found that the flaw dates back to version 14, which was released in September 2020.

When an iPhone or any other device connects to a network, it triggers a multicast message that is sent to all other devices on the network.

This message must include a MAC address. Starting with iOS 14, this address was by default different for each SSID.

To a casual observer, the feature seemed to work as advertised.

The "source" referenced in the request was a private Wi-Fi address. Looking a little further, it appeared that the actual MAC was still being broadcast, to all other connected devices. Mysk posted a short video showing the packet sniffer monitor traffic on the local network. When an iPhone enters an iPhone with iOS before 17.1 shares its real Wi-Fi MAC on port 5353/UDP.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).