NEWS

‘Trustjacking’ is the Dangerous New iPhone Hack You’ve Never Heard of

04/20/2018

9605

‘Trustjacking’ is the Dangerous New iPhone Hack You’ve Never Heard of


You might want to think twice before plugging your iPhone into a friends laptop for a quick charge.


Security researchers have discovered an all-new type of iOS hack called “trustjacking” that uses one of a little-known WiFi feature to access a device’s data, even when the targeted device isn’t in the same location anymore.


The way the hack works is an iPhone users plugs into the USB port on a friend’s computer. iOS asks if you want to trust the computer and mentions that it will have access to your data. You can then enable iTunes Wi-Fi Sync from the PC giving the devices the ability to communicate anytime they’re on the same network. Hence the name “trustjacking.”


iTunes Wi-Fi Sync is a useful feature when you’re at home and connected to a network you trust. But researchers at Symantec say “everything is possible”, as far as attacks go, if you trust the wrong computer.


The discovery of trustjacking


“We discovered this by mistake actually,” said Symantec’s Adi Sharabani in an interview with Wired.”Roy was doing research and he connected his own iPhone to his own computer to access it. But accidentally he realized that he was not actually connected to his own phone. He was connected to one of his team members’ phones who had connected their mobile device to Roy’s desktop a few weeks before. So Roy started to dig into what exactly he could do and find out if he were an attacker.”


Once your iPhone is synced to a hostile computer, the attacker could install malware on your phone or initiate a backup to pull all your photos, apps and text messages. Hackers could also use the flaw to watch your screen in real-time and take screenshots that sync back to their computer.


The good news is researchers haven’t found any instances of trustjacking attacks out in the wild yet. That doesn’t mean they don’t exist though. Apple tweaked the Wi-Fi Sync feature with iOS 11 so that it asks for the device’s passcode before trusting. Researchers say Apple needs to do more though to let users see what networks they’ve given trust to.


If you’re worried that you may have given a malicious computer access to your iPhone, you can refer: How to Protect Your iPhone from Trustjacking Attacks?


Source: cult of mac

Windows
Mac OS
iOS
Linux
3uTools
Win 64-bit For this device
V9.0 2025-11-11
Download
Win 32-bit For this device
V9.0 2025-11-11
Download
3uTools V3.18
2025-09-18
Please use the 3uTools PC client to install the iOS client:
1、 Install either the Windows or Mac version of 3uTools on your computer
2、 Open the PC client and connect your device to the computer via USB cable
3、 After the connection is successful, wait for the computer to automatically install the mobile app for the device, or locate “Install Mobile App” on the computer and manually click to install.
3uTools
deb file
v3.01 2025-11-20
Download
rpm file
v3.01 2025-11-20
Download
Windows
iOS
Android
3uAirPlayer
Win 64-bit For this device
V6.0.2 2025-11-19
Download
Win 32-bit For this device
V6.0.2 2025-11-19
Download
iOS Device Mirroring (No App Required)
1、 Install 3uAirplayer on the Windows PC
2、 Open Control Center and select Screen Mirroring
3、 From the list, choose your PC to start mirroring
4、 Or connect your iOS device to the PC via USB to begin mirroring
Scan to get "3uAirPlayer" App