iOS 15.2.1 fixes critical flaw — update your iPhone now

iOS 15
(Image credit: Shutterstock)

Update: Apple has release iOS 15.3.1 to fix a different problem with WebKit. 

If you have a recent iPhone or iPad then you’ll want to update it to the newly released iOS 15.2.1 and iPadOS 15.2.1, as this update fixes a nasty security flaw that could send your iPhone into a reboot spiral of death.

This bug was discovered by security researcher Trevor Spiniolas at the start of January and involved Apple’s HomeKit service, which provides the software interface between iPhones and iPads and some of the best smart home devices.

The vulnerability could allow hackers to set up a HomeKit compatible device with a very long name, some 500,000 characters in length, which would then trigger an iOS or iPadOS device to repeatedly crash when trying to connect to it. 

This denial of service attack would need to entice users to connect to a compromised HomeKit device, but curiosity when setting up smart home devices and the range at which they can be connected to spanning apartments or buildings, could make this a distinct possibility. However, the likely vector of attack would be a hacker using the Apple Home app to send an invite to targeted users asking them to join their ‘Home’ and thus be exposed to a network with a compromised HomeKit device. 

What’s more, as iOS and iPadOS backup HomeKit device names to iCloud, it could trigger affected iPhones and iPads to suffer from an endless loop of crashes. And rebooting or updating an affected iPhone or iPad won’t fix the problem either, with any attempt to backup from previously used iCloud data also triggering the crash cycle.

Ultimately, a factory reset would be needed and thus result in data loss; Spiniolas suggested this bug could be used by hackers to perform ransomware attacks, forcing victims to part with money or lose access to their iOS or iPadOS data.

But with iOS and iPadOS 15.2.1, the ability to put in excessively long HomeKit device names has been curtailed, and thus the bug has been squashed. So if you’ve yet to do it, we very much recommend you update to the latest version of iOS and iPadOS, as device running versions dating back to iOS 14.7 are vulnerable to this exploit.

And as ever, we suggest being cautious about the networks you connect your devices to. If an unknown user or device asks for permission to connect to your phone, tablet or laptop, then make sure you know it’s not malicious. We’d advise treating such situations with extreme caution until you know you’re connected to a trusted device or network.

TOPICS
Roland Moore-Colyer

Roland Moore-Colyer a Managing Editor at Tom’s Guide with a focus on news, features and opinion articles. He often writes about gaming, phones, laptops and other bits of hardware; he’s also got an interest in cars. When not at his desk Roland can be found wandering around London, often with a look of curiosity on his face. 

Read more
Apple iPhone 16 held in the hand.
iOS 18.3.1 — update your iPhone right now to fix critical zero-day vulnerability
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
iOS 18 home screen customization features
Apple will no longer allow users to downgrade from iOS 18.3 — here’s why
MacBook Pro 16-inch 2021 sitting on a patio table
Critical macOS flaw puts your data and cameras at risk — update right now
iPhone lock screen showing Control Center shortcuts and the iOS 18 logo
iOS 18.3 is available now — here’s the new features for your iPhone
Latest in iPhones
WWDC logo on yellow background
Apple WWDC 2025 date set for June 9 — iOS 19, Apple Intelligence and more expected
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Apple maps logo on iPhone screen
I avoided Apple Maps for trip planning — but these iOS 18 features are changing my mind
New emojis with iOS 18.4 beta release.
iOS 18.4 beta brings 8 new emoji to your iPhone — here's all the new options
An image of an iPhone screen showing the Safari app icon in the center
I got tired of Safari revealing my web searches in iOS 18.4 — this setting fixes that
iPhone Flip Concept
Foldable iPhone delays — there’s a bigger problem going on at Apple
Latest in News
Bill Gates in 2019
Bill Gates just predicted the death of every job thanks to AI — except for these three
NYTimes Connections
NYT Connections today hints and answers — Wednesday, March 26 (#654)
Gemini screenshot image
Google unveils Gemini 2.5 — claims AI breakthrough with enhanced reasoning and multimodal power
Samsung Galaxy Z Flip 6 review.
Samsung Galaxy Z Flip 7 design just teased in new cases leak — and the outer display is huge
Google Chrome
Chrome failed to install on Windows PCs, but Google has issued a fix — here's what happened
nyc spring day AI image
OpenAI just unveiled enhanced image generator within ChatGPT-4o — here's what you can do now