March 3, 2020 By Shane Schick 2 min read

Researchers estimate more than a billion devices may be vulnerable to a cyberthreat dubbed Krøøk that can intercept and decrypt Wi-Fi traffic using WPA2 connections.

ESET researchers said the vulnerability affects devices containing some of the most common Wi-Fi chips. This includes those from Broadcom and Cypress, whose vendor partners range from Amazon and Apple to Samsung and Asus, among others.

While many of these firms have already released patches, the risk of Krøøk spans both WPA2-Personal and WPA2-Enterprise protocols, according to the study.

How Krøøk Works

Traffic that travels through these kinds of Wi-Fi packets are normally considered secure, but researchers said the vulnerability takes advantage of disassociation, a term that describes the moment when a connection is interrupted. This could be due to a low Wi-Fi signal, for example.

In many cases, devices may encounter disassociation fairly often as people move from one Wi-Fi hotspot to another, but are configured to automatically reconnect quickly to known networks. Hackers could use Krøøk to prolong these periods and then receive Wi-Fi packets that they can decrypt using the all-zero key.

That said, cybercriminals would not be able to use the vulnerability to launch botnet attacks unless they are within close physical proximity to their victims, according to the research.

Other limitations include the fact that if the original communications were encrypted, that encryption would not be broken — only the Wi-Fi channel would be compromised. Victims would also likely detect suspicious activity on the Wi-Fi network if large communication streams were intercepted.

Close the Door on Krøøk

In order to protect against Krøøk, check for patches or software updates relating to the vulnerability, which has been given the unique ID CVE-2019-15126. Firmware updates may also be necessary in some cases, researchers added.

Next, by ensuring devices are using a more advanced security protocol such as AES-CCMP encryption, both consumers and businesses should be out of danger. Better yet, explore how a security intelligence platform can monitor and help address other kinds of Wi-Fi bugs.

More from

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

How secure are green data centers? Consider these 5 trends

4 min read - As organizations increasingly measure environmental impact towards their sustainability goals, many are focusing on their data centers.KPMG found that the majority of the top 100 companies measure and report on their sustainability efforts. Because data centers consume a large amount of energy, Gartner predicts that by 2027, three in four organizations will have implemented a data center sustainability program, which often includes implementing a green data center.“Responsibilities for sustainability are increasingly being passed down from CIOs to infrastructure and operations…

Are successful deepfake scams more common than we realize?

4 min read - Many times a day worldwide, a boss asks one of their team members to perform a task during a video call. But is the person assigning tasks actually who they say they are? Or is it a deepfake? Instead of blindly following orders, employees must now ask themselves if they are becoming a victims of fraud.Earlier this year, a finance worker found themselves talking on a video meeting with someone who looked and sounded just like their CFO. After the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today