Researcher details a now patched zero-click iOS device exploit using Apple's AWDL protocol which would grant attackers access to device hardware and data
A Google Project Zero researcher found a stunning vulnerability — Ever watch that movie, or play that video game …
Context & Ripple Effects
This disclosure closes a loop that Google Project Zero opened over a year ago: its five iOS exploit chains used in watering hole attacks against iOS 10 through 12 showed browser-based compromise at scale, and April's two actively exploited iOS 0-days present since at least iOS 6 added a remote zero-click flaw in Mail. The new report extends the pattern from apps to the OS itself — AWDL, the wireless protocol behind AirDrop, runs by default on every iPhone, so the attack surface here ships enabled on all devices rather than waiting for a user to open an attachment.
First-order effects
- Apple has already shipped the patch, so users who update are protected, but any device left on older iOS retains an exploitable radio protocol that requires no user interaction to target.
Second-order effects
- The finding forces Apple to treat always-on system protocols like AWDL as first-class audit targets alongside Mail and Safari, expanding its internal review surface after a year in which every disclosed chain came from outside researchers.
Third-order effects
- If zero-click exploitation keeps migrating from user-facing apps to ambient system services, the practical security boundary moves from what a user clicks to what a device broadcasts, raising the bar for how quickly vendors must patch protocol-level flaws.
The trend: iOS attack research is moving up the stack from browsers and mail clients to always-on system protocols, with Project Zero's disclosure cadence setting the pace for Apple's patching.