iOS Devices Can Freeze, Crash Due to a HomeKit Vulnerability

Security researcher Trevor Spiniolas said that Apple has been aware of the issue since August 10.

Advertisement
By Jagmeet Singh | Updated: 4 January 2022 14:42 IST
Highlights
  • iPhone and iPad users could be impacted due to HomeKit vulnerability
  • Users who don’t have a Home device can also be targeted
  • Apple users are advised to not accept any random HomeKit device invites

Apple has not yet confirmed a fix for the HomeKit vulnerability

Apple's iOS-based devices could go into a cycle of freezing and crashing and eventually become unusable due to a HomeKit vulnerability that has been exposed by a security researcher. The issue exists in all iOS versions, starting with iOS 14.7. iPhone users on the latest iOS version are also affected by the denial-of-service vulnerability, the researcher said. Apple is said to be aware of the issue and allegedly promise to address it before 2022. The flaw is, however, yet to be fixed.

Security researcher Trevor Spiniolas has detailed the scope of the HomeKit vulnerability that was initially reported to Apple on August 10 last year. The attacker can exploit the flaw and bring your iPhone or iPad in a cycle of freezing and crashing by connecting it with a HomeKit device that has an extensively lengthy name of around 500,000 characters, the researcher explained.

The iOS device is said to become unresponsive once it reads the device name. The attacker could also trigger the vulnerability by using an app to rename an existing HomeKit device. Alternatively, it could be exploited by sending an invite to a new HomeKit device that has a long name.

Advertisement

According to the researcher, Apple introduced a limit for the name an app or the user can set for a HomeKit device in iOS 15.1. This will help reduce the impact to some extent as the attacker couldn't impact users by triggering the vulnerability after renaming one of the connected HomeKit devices. But nonetheless, the issue can still impact users on the newer iOS versions if a HomeKit device with an extremely long name is connected via an invite.

Advertisement

The researcher also found that since Apple stores names of the connected HomeKit devices in iCloud, the issue persists even if a user restores an iOS device.

“If the device is restored but then signs back into the previously used iCloud, the Home app will once again become unusable,” the researcher said.

Advertisement

Spiniolas has created a video to give a brief look on the impact of the vulnerability even after restoring an iPhone.

Users can reject random invitations of HomeKit devices on their iPhone and iPad to avoid getting impacted by the vulnerability. Users who are already using smart home devices can also protect their hardware by disabling the setting Show Home Controls after going to the Control Centre.

Advertisement

In case you're already targeted by an attacker, the researcher advises that you can resolve the issue after restoring the affected device from Recovery or DFU Mode and set it up as normal without signing up into your iCloud account. Once signed up, you should sign into iCloud from settings and then disable the switch labelled Home immediately after signing in.

Spiniolas said that although it informed Apple about the bug in August, the company failed to bring a fix since the last deadline of January 1.

“I believe this bug is being handled inappropriately as it poses a serious risk to users and many months have passed without a comprehensive fix,” the researcher said.

In 2019, Apple credited Spiniolas for reporting a vulnerability in macOS Mojave. The researcher, however, accused the iPhone maker of giving insufficient response to the fresh vulnerability.

Gadgets 360 has reached out to Apple for a comment on the matter. This report will be updated when the company responds.


What are the best phones of 2021? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Top OTT Releases of the Week: Kantara Chapter 1, Lokah Chapter 1, Idli Kadai, and More
  2. iQOO Neo 11 With Snapdragon 8 Elite SoC Launched: Price, Specifications
  3. Vivo X300 Series Launching Today: Everything You Need to Know
  4. Reliance Offers Free 18-Month Google AI Pro with Gemini, Veo to Jio Users
  5. Gemini 3 AI Model Will Be Released Soon, Says Google CEO Sundar Pichai
  6. Realme GT 8 Pro Will Launch in India in November With This Chipset
  7. Lava Agni 4 With Metal Design and Flat Edges Teased Ahead of Debut
  8. Samsung Galaxy S26 Series Teased to Launch With These Notable Upgrades
  9. Grammarly Rebrands to Superhuman, Introduces New Agentic AI Assistant
  10. Snapdragon 8 Gen 5 Chipset Key Specs, Benchmarks Leak
  1. Canva Introduces Revamped Video Editor, New AI Tools and a Marketing Platform
  2. Bitchat Becomes Jamaica’s Go-to App as Hurricane Melissa Cripples Communication
  3. Google Maps Is Reportedly Developing a New Power Saving Mode for Navigation
  4. Take-Two CEO Says AI Won't Be 'Very Good' at Making a Game Like Grand Theft Auto
  5. Reliance Users to Get Free Google AI Pro Access for 18 Months Worth Rs. 35,100 With Gemini, Veo Features
  6. Meta’s VR Headsets and AI Glasses Cost the Company $4.4 Billion in Q3 2025
  7. iQOO Neo 11 With 7,500mAh Battery, Snapdragon 8 Elite Chip Launched: Price, Specifications
  8. Telegram Founder Pavel Durov Launches Cocoon, a Decentralised AI Project on TON
  9. Hedda (2025) Now Available for Streaming on Amazon Prime Video: What You Need to Know
  10. Samsung Galaxy S26 Series Teased to Launch With Upgraded Chipset, Camera, and AI Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.