FragAttacks: Wi-Fi Vulnerabilities Impacting Almost All Connected Devices Discovered, Windows Gets Patched

Security researcher Mathy Vanhoef has found and reported the new set of Wi-Fi vulnerabilities online.

Advertisement
By Jagmeet Singh | Updated: 13 May 2021 17:36 IST
Highlights
  • Mathy Vanhoef has detailed the vulnerabilities on a dedicated site
  • There is a range of 12 different vulnerabilities
  • Wi-Fi vulnerabilities have been patched to some extent by Microsoft

Wi-Fi vulnerabilities could impact devices using even newer WPA2 and WPA3 standards

Photo Credit: Pixabay/ USA Reiseblogger

Multiple vulnerabilities have been discovered that are claimed to affect all modern Wi-Fi security protocols and impact a range of devices ranging from smartphones to routers and even small IoT devices. The vulnerabilities have been brought into notice by a Belgian cybersecurity expert who previously gained popularity for co-finding the widespread Wi-Fi vulnerabilities in the WPA2 protocol that resulted in key reinstallation attacks — commonly called KRACKs. Those security loopholes were fixed by most of the tech companies to avoid leaking of user data.

Mathy Vanhoef has found the new set of Wi-Fi vulnerabilities that he calls “fragmentation and aggregation attacks” — or FragAttacks in short. The researcher detailed the flaws through a dedicated site, as initially reported by Gizmodo.

According to the details provided online, there are 12 different security issues that could potentially leak user data or allow hackers to gain access to a device. Three of the discovered vulnerabilities are design flaws in the Wi-Fi standard and are thus believed to impact most devices out in the market, Vanhoef said. However, the researcher also found several other vulnerabilities that exist due to programming-level issues in Wi-Fi devices.

Advertisement

In one case, Vanhoef noted that a hacker could exploit Wi-Fi networks by injecting plaintext aggregated frames that look like handshake messages on a system. He also mentioned another flaw that could be exploited by tricking victims into processing encrypted transported data unintentionally.

Advertisement

The issues could impact users on Wi-Fi networks based on WPA2 or even WPA3 standards, the researcher said. A video demonstration of the key flaws has also been provided by the researcher.

Thankfully, Vanhoef underlined that the design flaws he found are hard to abuse as attackers require user interaction or need to use some uncommon network settings. The vulnerabilities were reported to various device makers and some of them have provided fixes for their devices. Similarly, the researcher informed the Wi-Fi Alliance and helped prepare security updates during a nine-month-long coordinated disclosure.

Advertisement

Although the exact period for how long the vulnerabilities exist is unknown, Vanhoef said on his site that even the original security protocol of Wi-Fi — WEP — is affected. It was notably released back in 1997.

Users are advised to install the latest software updates on their Wi-Fi devices to patch the loopholes. Microsoft has issued updates to address three of the more common vulnerabilities in Windows 10, Windows 8.1, and Windows 7. You should install these updates on your system to stay protected.

Advertisement

Similarly, companies including Cisco, Ruckus, Intel, Lenovo, Netgear, Samsung, and Synology have released patches for their devices. Given the reputation of Vanhoef and thanks to his background with discovering KRACK attacks, many other companies are likely to release patches for their devices in the coming days. Meanwhile, in case if a user doesn't get an update for their devices, Vanhoef recommended that the issues can be mitigated by visiting only websites that use HTTPS, have the latest updates in place, and must not reuse passwords.


Why did LG give up on its smartphone business? We discussed this on Orbital, the Gadgets 360 podcast. Later (starting at 22:00), we talk about the new co-op RPG shooter Outriders. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, and wherever you get your podcasts.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Starlink Will Offer Unlimited Satellite Internet in India at This Price
  2. OnePlus Pad Go 2 First Impressions
  3. OnePlus 15R Roundup: Price in India, Specs and Everything We Know So Far
  4. Xiaomi 17 Listed on Geekbench, Here's When It Might Launch in India
  5. Jolla Phone Launched With 5,500mAh Replaceable Battery, Sailfish OS 5
  6. OnePlus Pad Go 2 Key Features Revealed: Here's When It Goes on Sale in India
  7. Motorola Edge 70 With 5.99mm Slim Profile Will Launch in India on This Date
  8. Vivo S50, Vivo S50 Pro Mini Set to Launch on This Date
  9. Airtel Partners With Google to Launch RCS Messaging in India
  10. Realme Narzo 90 Series 5G India Launch Announced
  1. Francis Lawrence’s The Long Walk (2025) Now Available for Rent on Prime Video and Apple TV
  2. Nicolas Cage Starrer Spider-Noir Set to Release on Prime Video in 2026
  3. Devi Chowdhurani OTT Release Date: When and Where to Watch Srabanti Chatterjee’s Period Drama Online?
  4. OnePlus Pad Go 2 Key Specifications and Sale Date Revealed; Will Feature Dimensity 7300-Ultra SoC
  5. OpenAI Claims Increased Enterprise Usage Amid CEO’s Code Red Declaration
  6. Samsung's One UI 8.5 Beta Update Rolls Out to Galaxy S25 Series in Multiple Regions
  7. Elon Musk Says Grok 4.20 AI Model Could Be Released in a Month
  8. Xiaomi 17 Global Variant Listed on Geekbench, Tipped to Launch in India by February 2026
  9. James Gunn's Superman to Release on JioHotstar on December 11: What You Need to Know
  10. The Boys Season 5 OTT Release Date: When and Where to Watch the Final Season Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.