Apple Fixes AirDrop Bug That Locked iPhones in Inescapable Loop
Apple releases iOS 13.3 to patch a denial-of-service flaw that traps devices in a continuous file-sharing prompt. The fix adds rate-limiting to prevent attackers from overwhelming nearby iPhones and iPads.
Apple releases iOS 13.3 to patch an AirDrop flaw that allows attackers to temporarily lock users out of their iPhones and iPads. Discovered by researcher Kishan Bagaria and dubbed "AirDoS," the bug exploits the file-sharing feature by bombarding a device with continuous file transfer requests. Because iOS previously lacks a limit on incoming requests, the persistent file acceptance prompt prevents the owner from using their device.
Devices set to receive AirDrop files from "Everyone" face the highest risk from this denial-of-service attack. The file accept box is so persistent that victims find it nearly impossible to navigate the settings to turn off Bluetooth and stop the bombardment. The only immediate workaround during an active attack is to physically move out of the attacker's wireless range so the Bluetooth connection drops.
The latest update resolves the issue by implementing a rate-limit that blocks a barrage of file requests over a short period. Although the bug effectively denies users access to their devices, Apple states it is not strictly a security vulnerability and therefore does not assign it a CVE score. Instead, the company publicly acknowledges Bagaria's findings in its official security advisory for the update.