Apple’s devices that run iOS, including iPhone and iPad devices, can be affected by a vulnerability in HomeKit. Security researcher Trevor Spiniolas has detailed the exploit, in which an attacker can bring an iPhone or iPad to a crashing loop. This attack is done by connecting to a HomeKit device with a name that is 500,000 characters long.
According to Spiniolas, Apple has introduced a character limit for HomeKit devices in iOS 15.1, which should help mitigate the issue. However, the issue can still affect users if a HomeKit device which has already been given a long name sends an invite.
Once an iOS device reads the device name, it is said to become unresponsive. The issue can even persist across restarts, as Apple saves HomeKit device names in iCloud. If a user restores a previously-affected iOS device, the Home app will once again become unusable when it restores the long device name.
Also Read: CES 2022: Samsung launches Galaxy S21 FE - check specs, price
According to the researcher, users can reject random invitations of HomeKit devices on their iPhone and iPad devices to avoid being affected.
In case an iOS device has already been affected, users can restore it from Recovery or DFU Mode and set it up without signing into their iCloud account. Once set up, users can sign into their iCloud account, and then disable the ‘Home’ switch immediately.
Spiniolas said that Apple had been informed of the bug as early as August 10, but had not fixed the issue even by January 1. Apple is yet to comment on this issue.