Apple says iOS 15.2.1 fixes its HomeKit denial of service vulnerability

HomeKit Router splash screen displayed on an iPhone
HomeKit Router splash screen displayed on an iPhone (Image credit: Christopher Close / iMore)

What you need to know

  • Apple has released iOS 15.2.1 to the public.
  • iOS 15.2.1 fixes a bug that caused iPhones and iPads to restart when a HomeKit accessory had a name with more than 500,000 characters in its name.
  • All users should install iOS 15.2.1 as soon as possible.

Apple says that its new iOS 15.2.1 update patches a HomeKit denial of service vulnerability that could make an iPhone or iPad crash repeatedly. The release is available for download now and should be installed as soon as possible.

The vulnerability was reported by security researcher Trevor Spinoloas and was found to be an issue when a HomeKit device's name was changed to something that was more than 500,000 characters long. Such a name caused what was essentially a Denial of Service attack and caused iPhones and iPads to repeatedly crash.

When the name of a HomeKit device is changed to a large string (500,000 characters in testing), any device with an affected iOS version installed that loads the string will be disrupted, even after rebooting. Restoring a device and signing back into the iCloud account linked to the HomeKit device will again trigger the bug.

Apple now says that the iOS 15.2.1 update fixes the issue and will prevent it from happening again. The same update also reportedly ensures that CarPlay apps work properly when tapped. Another issue that prevented images from loading when sent via iCloud Link has also been dealt with in this release.

Those who are yet to update their devices can do so by heading into the Settings, tapping General, and then Software Update.

Oliver Haslam
Contributor

Oliver Haslam has written about Apple and the wider technology business for more than a decade with bylines on How-To Geek, PC Mag, iDownloadBlog, and many more. He has also been published in print for Macworld, including cover stories. At iMore, Oliver is involved in daily news coverage and, not being short of opinions, has been known to 'explain' those thoughts in more detail, too. Having grown up using PCs and spending far too much money on graphics card and flashy RAM, Oliver switched to the Mac with a G5 iMac and hasn't looked back. Since then he's seen the growth of the smartphone world, backed by iPhone, and new product categories come and go. Current expertise includes iOS, macOS, streaming services, and pretty much anything that has a battery or plugs into a wall. Oliver also covers mobile gaming for iMore, with Apple Arcade a particular focus. He's been gaming since the Atari 2600 days and still struggles to comprehend the fact he can play console quality titles on his pocket computer.

Latest in iOS 15
Iphone 13 mini and iPhone 13
Apple is no longer signing iOS 15.5 for the iPhone
iPhone 12 Pro review
How to download the iOS 15.7.1 Release Candidate to your iPhone
Ios 15 Focus Hero
How to download iOS 15.6 public beta 5 to your iPhone
App Store
Apple's iPhone subscription page is now much easier to use and read
Facetime Icon Iphone Xs Max Hero
How to use Portrait mode in FaceTime on iPhone and iPad
Iphone Safari Start Page Hero
How to customize your start page in Safari on iPhone and iPad
Latest in News
iMore Logo
One more thing… Goodbye from iMore
Jony Ive
Jony Ive’s OpenAI hardware device could be his next world-changing design
NEBULA Cosmos 4K SE with Apple TV
This new 4K projector is tempting me to replace my LG C2 TV, just so I can watch Slow Horses on a 200-inch display
VisionOS 2 app reorganization
visionOS 2 is the first major software update for Apple Vision Pro, and now it's available
macOS Sequoia
macOS Sequoia (version 15) is now available for your Mac with some big upgrades
watchOS 11
watchOS 11 is now rolling out to all Apple Watch users with the Series 6 or newer