Skip to main content

iOS 11.2.1 and tvOS 11.2.1 are now available, update restores HomeKit sharing following vulnerability fix

Apple has released iOS 11.2.1 for iPhone and iPad. The software update restores remote access in HomeKit for shared users which was temporarily disabled last week to address a vulnerability in Apple’s smart home framework that allowed unauthorized access in certain circumstances. Apple has also released tvOS 11.2.1 which is likely related to the fix.

9to5Mac reported on the vulnerability, which allowed unauthorized access to smart home accessories including locks and garage door openers, last week after seeing a demonstration in the shipping version of iOS 11.2.

Apple promptly resolved the issue server side so HomeKit users needed to take no action to ensure security. The server side fix temporarily disabled remote access for shared users in HomeKit, however, and users can update to the latest version of iOS to restore that functionality.

Here are the official release notes:

iOS 11.2.1 fixes bugs including an issue that could disable remote access to shared users of the Home app.

And here is what the security document describes:

HomeKit

Available for: iPhone 5s and later, iPad Air and later, and iPod touch 6th generation

Impact: A remote attacker may be able to unexpectedly alter application state

Description: A message handling issue was addressed with improved input validation.

CVE-2017-13903: Tian Zhang

Both tvOS 11.2.1 and iOS 11.2.1 should be rolling out to all users now. Devices on beta versions may need to remove beta profiles then reboot to see the updates.


Subscribe to 9to5Mac on YouTube for more Apple news:

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Zac Hall Zac Hall

Zac covers Apple news, hosts the 9to5Mac Happy Hour podcast, and created SpaceExplored.com.

Manage push notifications

notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications
notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications