Bug in Cypress and Broadcom Wi-Fi chips meant billions of devices, many now patched, were left open to eavesdropping; Apple, Amazon, and others were affected
Dan Goodin / Ars Technica :
Context & Ripple Effects
This is the third time in three years that Broadcom's Wi-Fi silicon has anchored a mass-exposure story: a Project Zero chipset flaw hit Android devices in 2017, followed months later by a [[a:920973|now-patched Broadcom flaw that opened roughly a billion iPhones and Android phones to a fully remote worm]]. The new report extends the pattern to Cypress chips and shifts the impact from remote code execution to passive eavesdropping, with Apple and Amazon among the affected vendors.
The finding also lands on top of a parallel run of wireless-protocol failures — the KRACK exploits against WPA2, a cross-vendor Bluetooth encryption bug hitting Apple, Intel, and Qualcomm stacks, and a years-old Realtek Wi-Fi driver flaw in Linux devices — making chip and driver firmware the recurring common denominator rather than any single vendor's code.
First-order effects
- Apple, Amazon, and other device makers had to push patches through their own update channels, since the vulnerable code lives in Cypress/Broadcom chip firmware their customers cannot update directly; unpatched devices stay open to traffic eavesdropping.
Second-order effects
- Broadcom and Cypress face repeated coordinated-disclosure cycles that force them to harden firmware and get fixes into OEM pipelines faster, while OS vendors absorb the patching burden for hardware they did not design.
Third-order effects
- If the pattern holds, wireless chip firmware becomes a first-class audit target alongside OS code, pressuring silicon vendors toward longer support commitments and pushing buyers to weigh firmware-update track records when choosing components.
The trend: Wireless connectivity is proving chronically fragile at the silicon and firmware layer, shifting security responsibility upstream from app and OS developers to chip vendors whose fixes reach users only through OEM update chains.