Researchers from Eset at the ongoing conference information about () in wireless chips from Cypress and Broadcom, allowing for the decryption of intercepted Wi-Fi traffic protected by the WPA2 protocol. The vulnerability is codenamed Kr00k. This issue affects FullMAC chips (where the Wi-Fi stack is implemented on the chip side rather than the driver) used in a wide range of consumer devices, from well-known smartphone manufacturers (Apple, Xiaomi, Google, Samsung) to smart speakers (Amazon Echo, Amazon Kindle), boards (Raspberry Pi 3), and wireless access points (Huawei, ASUS, Cisco).
The vulnerability is caused by improper handling of encryption keys during disconnection () of the device from the access point. Upon disconnection, the session key (PTK) stored in the chip's memory is reset, as no further data will be sent in the current session. The essence of the vulnerability is that data remaining in the transmission buffer (TX) is encrypted using the already cleared key, which consists solely of zeros and can therefore be easily decrypted if intercepted. The empty key is applied only to residual data in the buffer, which is several kilobytes in size.
Thus, the attack is based on artificially sending specific frames that trigger disassociation and intercepting the subsequently sent data. Disassociation is typically used in wireless networks for switching from one access point to another during roaming or when the connection with the current access point is lost. Disassociation can be triggered by sending a control frame, which is transmitted in an unencrypted form and does not require authentication (the attacker only needs to have access to the Wi-Fi signal but does not need to be connected to the wireless network). The attack has only been tested using the WPA2 protocol; the possibility of executing the attack on WPA3 has not been verified.
According to preliminary estimates, the vulnerability may potentially affect billions of widely used devices. The issue does not manifest on devices with Qualcomm, Realtek, Ralink, and Mediatek chips. Traffic decryption is possible when a vulnerable client device connects to a problem-free access point, as well as when a non-vulnerable device connects to an access point exhibiting the vulnerability. Many consumer device manufacturers have already released firmware updates addressing the vulnerability (for instance, Apple the vulnerability back in October of last year).
It is important to note that the vulnerability affects encryption at the wireless network level and only allows for the analysis of user-established unencrypted connections, but does not compromise connections with application-level encryption (HTTPS, SSH, STARTTLS, DNS over TLS, VPN, etc.). The risk of an attack is further diminished by the fact that an attacker can only decrypt a few kilobytes of data that were in the transmission buffer at the time of disconnection. For successful interception of confidential data sent over an unencrypted connection, the attacker must either know the exact timing of data transmission or repeatedly initiate disconnections from the access point, which would be noticeable to the user due to constant wireless connection restarts.
Some of the devices tested by Eset for attack vulnerability include:
- Amazon Echo 2nd gen
- Amazon Kindle 8th gen
- Apple iPad mini 2
- Apple iPhone 6, 6S, 8, XR
- Apple MacBook Air Retina 13-inch 2018
- Google Nexus 5
- Google Nexus 6
- Google Nexus 6S
- Raspberry Pi 3
- Samsung Galaxy S4 GT-I9505
- Samsung Galaxy S8
- Xiaomi Redmi 3S
- Wireless routers ASUS RT-N12, Huawei B612S-25d, Huawei EchoLife HG8245H, Huawei E5577Cs-321

Source: opennet.ru
