/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Apple fixed an old iOS bug that let nearby wireless routers gather real MAC addresses even when Private Wi-Fi Address is enabled, including in Lockdown Mode

“From the get-go, this feature was useless,” researcher says of feature put into iOS 14.  —  Three years ago, Apple introduced …

Ars Technica Dan Goodin

Context & Ripple Effects

Apple’s Private Wi‑Fi Address feature was meant to limit device identification on local networks, but the newly fixed flaw meant nearby routers could still obtain the hardware MAC address—even under Lockdown Mode. That turns a privacy control into an incomplete boundary rather than a reliable one.

The issue fits a longer run of Apple Wi‑Fi fixes, from a network-name bug that disabled iPhone Wi‑Fi to chip-level Wi‑Fi flaws affecting billions of devices. The difference here is that the immediate risk is persistent local identification, not simply loss of connectivity or device compromise.

First-order effects

  • iPhone users receiving the fix regain the intended separation between a network-facing randomized address and the device’s real MAC address on nearby Wi‑Fi infrastructure.
  • Network operators and anyone operating nearby wireless routers lose an avenue to associate affected iOS devices with a stable hardware identifier while the privacy setting is enabled.

Second-order effects

  • The finding raises the bar for Apple’s privacy-feature validation: protections advertised as usable in Lockdown Mode must be tested against lower-level Wi‑Fi behavior, not only app- and OS-level controls.
  • Organizations that rely on MAC-based Wi‑Fi identification may see less consistent device recognition as patched iPhones stop exposing their permanent address in this scenario.

Third-order effects

  • The episode reinforces that wireless privacy depends on implementation across the networking stack; randomized identifiers provide limited protection when underlying protocol behavior can reveal a stable identifier.
  • If similar gaps continue to surface, privacy modes will increasingly be judged on measurable resistance to local-network tracking rather than on the presence of a setting alone.

The trend: Consumer platforms are moving from privacy controls as interface features toward privacy controls that must hold up against network-layer identification techniques.

Discussion

  • @lapcatsoftware@mastodon.social Jeff Johnson on mastodon
    “On Wednesday, the world learned that the feature has never worked as advertised.”  —  Where have we heard that before?  Oh, let's see, how about macOS App Management, for example.  —  Apple is very good at security theater.  —  https://arstechnica.com/...
  • @mysk_co @mysk_co on x
    “Apple hasn't explained how a failure as basic as this one escaped notice for so long. The advisory the company issued Wednesday said only that the fix worked by ‘removing the vulnerable code.’” https://arstechnica.com/...
  • @cryptonator1337 @cryptonator1337 on x
    ‘Three years ago, Apple introduced a privacy-enhancing feature that hid the Wi-Fi address of iPhones and iPads when they joined a network. On Wednesday, the world learned that the feature has never worked as advertised.’ https://arstechnica.com/...
  • @gaetanoz Gaetano Zappulla on x
    Despite promises that this never-changing address would be hidden and replaced with a private one that was unique to each SSID, Apple devices have continued to display the real one, which in turn got broadcast to every other connected device on the network https://arstechnica.com…
  • @vanhoefm @vanhoefm on x
    This new iPhone flaw is about tracking users *while connected* to a Wi-Fi network. Even with the CVE fixed, that's IMO hard to fully prevent. Usage of random MAC addresses while *scanning* for Wi-Fi networks seems to have properly worked all the time. https://arstechnica.com/...
  • @benhammersley Ben Hammersley on x
    @UK_Daniel_Card Ohh yeah, I'm confusing two things before coffee. There was a cve patched with 17.1 where devices with Private (MAC) Address set to on, leaked their true MAC address on 5353 anyway. Not IP. (Intrigued how LinkedIn can bypass private relay though.) https://arstechn…
  • @evacide Eva on x
    “Three years ago, Apple introduced a privacy-enhancing feature that hid the Wi-Fi address of iPhones and iPads when they joined a network. On Wednesday, the world learned that the feature has never worked as advertised.” https://arstechnica.com/...
  • @mysk_co @mysk_co on x
    NEW: Private Wi-Fi addresses had been useless ever since they were introduced in iOS 14.  When an iPhone joins a network, it sends multicast requests to discover AirPlay devices in the network.  In these requests, iOS sends the device's real Wi-Fi MAC address.  Exposure of a devi…
  • r/apple r on reddit
    iPhones have been exposing your unique MAC despite Apple's promises otherwise
  • r/technology r on reddit
    iPhones have been exposing your unique MAC despite Apple's promises otherwise — “From the get-go, this feature was useless,” researcher says of feature put into iOS 14
  • r/gadgets r on reddit
    iPhones have been exposing your unique MAC despite Apple's promises otherwise |  “From the get-go, this feature was useless,” researcher says of feature put into iOS 14.
  • r/privacy r on reddit
    iPhones have been exposing your unique MAC despite Apple's promises otherwise |  “From the get-go, this feature was useless,” researcher says of feature put into iOS 14.