Apple Geolocation API Exposes Wi-Fi Access Points Worldwide
ID: 6fcec3eb-4291-5cc7-a216-ade310889683
STIX ID: report--6fcec3eb-4291-5cc7-a216-ade310889683
Feed Name: Dark Reading
Threat Score
Research presented at Black Hat 2024 demonstrates that Apple's unauthenticated Wi‑Fi Positioning System (WPS) API can be abused to map hundreds of millions of Wi‑Fi access points worldwide by brute‑forcing BSSIDs and using returned nearby results for "snowball sampling," exposing privacy and intelligence risks; mitigations include BSSID randomization, using the "_nomap" SSID opt‑out, and design changes such as authentication/rate limiting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
