logo

Apple Geolocation API Exposes Wi-Fi Access Points Worldwide

ID: 6fcec3eb-4291-5cc7-a216-ade310889683

STIX ID: report--6fcec3eb-4291-5cc7-a216-ade310889683

Feed Name: Dark Reading

Threat Score
60/100

Date Published: 2024-07-08

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Research presented at Black Hat 2024 demonstrates that Apple's unauthenticated Wi‑Fi Positioning System (WPS) API can be abused to map hundreds of millions of Wi‑Fi access points worldwide by brute‑forcing BSSIDs and using returned nearby results for "snowball sampling," exposing privacy and intelligence risks; mitigations include BSSID randomization, using the "_nomap" SSID opt‑out, and design changes such as authentication/rate limiting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.