A now-patched flaw in Broadcom WiFi chips opened 1B iPhones and Android devices to a fully remote worm attack
Wi-Fi chips used in iPhones and Android may revive worm attacks of old. — LAS VEGAS—It's not often that a security researcher devises an attack that can unleash …
Context & Ripple Effects
This Black Hat disclosure completes an arc that began in April, when Project Zero flagged the same Broadcom WiFi chipset flaw and Google shipped an Android patch while Apple quietly fixed it in iOS 10.3.1. What was then a serious remote-hack bug is now demonstrated as something worse: a fully self-propagating worm that needs no user interaction, putting roughly a billion iPhones and Android devices in scope until their firmware updates land.
The reason this matters beyond one bug is that Broadcom's WiFi silicon sits inside both ecosystems at once — a single chip-level defect crosses the iOS/Android divide that usually contains such incidents, and later coverage of a Cypress and Broadcom WiFi bug exposing billions of devices to eavesdropping shows shared radio firmware keeps producing exactly this class of cross-platform event.
First-order effects
- Owners of unpatched iPhones and Android devices were exposed to infection simply by having WiFi enabled near an attacker, with no click required — the patch from Broadcom, distributed through Apple's and Google's OS updates, is the only immediate defense.
- Apple and Google had to push radio-firmware fixes through their respective update pipelines, making carrier and user update behavior the bottleneck for closing the hole.
Second-order effects
- Because the vulnerable code lives in Broadcom's chip firmware rather than either operating system, every OEM shipping that silicon inherits the remediation burden — the same dynamic that resurfaced when Cypress and Broadcom chips left billions of devices open to eavesdropping.
- A wormable WiFi exploit raises the stakes for adjacent radio stacks too: researchers have since shown comparable reach in Realtek Linux drivers and in Bluetooth authentication, pressuring all short-range wireless vendors toward faster firmware disclosure cycles.
Third-order effects
- If shared WiFi silicon keeps turning single firmware flaws into billion-device exposure events, radio firmware becomes a first-class security surface that OS vendors must own end-to-end rather than trust to chip suppliers.
- Protocol-implementation bugs like the IEEE 802.11 injection flaw found in routers and operating systems point the longer arc toward hardened, formally scrutinized wireless stacks — and toward regulators treating unpatched radio firmware in consumer devices as a structural risk.
The trend: Shared WiFi chip firmware is emerging as a cross-platform single point of failure, where one vendor's bug can worm across both major mobile ecosystems at once.