Apple's AirDrop, Wi-Fi Password Sharing Features Could Leak Your Phone Number: Report

The security loopholes are claimed to exist not only on iPhone but also on MacBook, Apple Watch, and AirPods.

Advertisement
By Jagmeet Singh | Updated: 2 August 2019 18:50 IST
Highlights
  • Cybersecurity firm Hexway has claimed the vulnerabilities
  • Apple devices broadcast partial SHA256 hash of phone numbers via AirDrop
  • Attackers can allegedly use the hash to recover the phone number

AirDrop is designed to enable easy sharing of content between two Apple devices

Apple has for a long time offered AirDrop on its iOS and Mac devices to enable easy content sharing between two devices. Similarly, it allows iPhone and Mac users to share their Wi-Fi passwords with a single tap. While both features are designed to enhance the user experience, a new report claims that an attacker can use AirDrop and Wi-Fi password sharing broadcasts to obtain potentially sensitive data, including phone numbers. It is also said that once Bluetooth is turned on, Apple devices broadcast device details, such as phone status and Wi-Fi status.

The report published by cyber-security firm Hexway claims that simply turning on Bluetooth enables attackers to access information about the phone status, battery information, Wi-Fi status, buffer availability, and OS version among other information. The loophole is claimed not to exist only on iPhone units, but also on MacBook, Apple Watch, and AirPods units. All this data is allegedly sent in Bluetooth Low Energy packets.

Alongside the Bluetooth vulnerability, the report by Hexway says that when using AirDrop, Apple users broadcast a partial SHA256 hash of their phone number. An attacker can use the hash to recover the original phone number and even contact the user in iMessage or obtain the name of the user, the report claims, detailing the steps involved of recovering a phone number from a partial hash.

Advertisement

In case of using the Wi-Fi password sharing feature, the report claims Apple devices send partial SHA256 hashes of phone number, Apple ID, and email addresses associated with them. "Only the first 3 bytes of the hashes are sent, but that's enough to identify your phone number (actually, the number is recovered from HLR requests that provide phone number status and region)," the researchers claimed in their report, adding the steps that can be taken to convert the no details about whether email addresses can be recovered are mentioned. Hexway researchers have also released a few videos on YouTube to detail the issues.

Advertisement

 

A proof-of-concept (PoC) has been included with Hexway's report to demonstrate the information broadcast. Ars Technica's Dan Goodin says the PoC, when used by Errata Security CEO Rob Graham, showed that within a minute or two, details of more than a dozen of nearby iPhone and Apple Watch models was captured on a system.

Advertisement

 

Apple has provided a Contacts Only option in AirDrop that limits its access. Similarly, it is advisable to disable Bluetooth if it's not in use. This is certainly not possible if you own an Apple Watch or use AirPods regularly.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apple AirDrop, AirDrop, Apple, iOS, Mac
Advertisement

Related Stories

Popular Mobile Brands
  1. Bridgerton Season 4 Premieres in Two Parts on Netflix: See Details
  2. OnePlus 15R Storage Options Leaked: Here's How Much It Might Cost in India
  3. Motorola Edge 70 With 5,000mAh Battery Launched in India at This Price
  4. Jio Launches Happy New Year 2026 Prepaid Plans: Check Price, Benefits
  5. Scientists Track Glowing Green Comet 3I/ATLAS as It Nears Earth
  6. Nandamuri Balakrishna's Akhanda 2 Arrives on OTT in 2026
  7. ChatGPT's Adult Mode Might Arrive in Early 2026
  1. Motorola Edge 70 Launched in India With 5,000mAh Battery, 50-Megapixel Triple Rear Cameras: Price, Specifications
  2. ChatGPT Adult Mode to Reportedly Be Rolled Out in 2026, to Participate in Erotic Roleplays
  3. OnePlus 15R Price in India, Storage Configurations Leaked Days Before Launch in India
  4. Reliance Jio Launches Happy New Year 2026 Plans With Unlimited 5G Access, Google Gemini Pro
  5. Early Earth’s Deep Mantle May Have Held More Water Than Previously Believed, Study Finds
  6. Nandamuri Balakrishna's Akhanda 2 Arrives on OTT in 2026: When, Where to Watch the Film Online?
  7. Single Papa Now Streaming on OTT: All the Details About Kunal Khemu’s New Comedy Drama Series
  8. Scientists Study Ancient Interstellar Comet 3I/ATLAS, Seeking Clues to Early Star System Formation
  9. Bridgerton Season 4 to Release in Two Parts on OTT: When and Where to Watch It Online?
  10. Spider-Like Scar on Jupiter’s Moon Europa Could Indicate Subsurface Salty Water
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.