Get all your news in one place.
100’s of premium titles.
One app.
Start reading
The Guardian - UK
The Guardian - UK
Technology
Samuel Gibbs

Apple fixes HomeKit bug that allowed remote unlocking of users' doors

welcome mat
To exploit the bug the attackers would need to know the email address associated with the Apple ID of the homeowner and knowledge of how the system worked. Photograph: Image Source/Getty Images/Image Source

Apple has been forced to fix a security hole within its HomeKit smart home system that could have allowed hackers to unlock users’ smart locks or other devices.

The bug within iOS 11.2 permitted unauthorised remote control of HomeKit-enabled devices. Such devices include smart lights, plugs and other gadgets, but also includes smart locks and garage door openers.

An Apple spokesperson said: “The issue affecting HomeKit users running iOS 11.2 has been fixed. The fix temporarily disables remote access to shared users, which will be restored in a software update early next week.”

The company said the temporary fixed was made server side, meaning that users do not have to do anything for it to take effect, but also that it breaks some functionality of the system.

The vulnerability, disclosed to 9to5Mac, required at least one iPad, iPhone or iPod Touch running the latest software version iOS 11.2 to have connected to the iCloud account associated with the HomeKit system. Previous versions of iOS appear not to have been affected. To exploit the bug the attackers would need to know the email address associated with the Apple ID of the homeowner and knowledge of how the system worked.

Experts said that while issues with smart-home systems such as this impact consumer confidence in smart locks and other security devices, traditional locks can also be easily undermined with traditional picking techniques.

The security bug is just the latest in a series of issues affecting Apple’s software on both its iPhone and Mac computers. Since November, iPhone and iPad users have been plagued with bugs affecting the autocorrect system, including issues typing the word “it” and the letter “I”, having it replaced with odd symbols.

Apple was also forced to apologise after a serious security flaw that allowed anyone to take control of a Mac running the latest version of macOS High Sierra with a blank password was revealed. The company rushed out a fix for the security bug, which then broke the file sharing system, which itself needed fixing in a later software update.

“We greatly regret this error and we apologise to all Mac users, both for releasing with this vulnerability and for the concern it has caused. Our customers deserve better,” Apple said at the time.

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.