Security researcher discovers Apple battery hack

17:26 • 26.07.11

A security researcher has discovered a hack that could lead to bricked batteries and fire hazards in Apple hardware.

Charlie Miller, a security researcher known for repeated hacks of the Safari Browser at the annual Pwn2Own hacking competition, has come across a battery hack which exposes a vulnerability in the Smart Battery system used in Apple products, Mybroadband.co.za reported.

The Smart Battery system makes use of a controller that monitors a variety of parameters in the battery, such as charge levels, internal voltage and current as well as thermal characteristics.

The hack is an error on Apple’s part, as they used the default user name and password for the Smart Battery system, allowing potential hackers to rewrite the firmware of the SBS. This can modify the battery’s internal parameters and could lead to a dead battery, or in the worst case scenario, an explosion.

The hack could also potentially open the Smart Battery system to malware, which can ‘hide’ from a device format or even drive swap, and infect the new system upon startup.

Miller plans to detail his findings at the Black Hat security conference in early August 2011.
 

Security researcher discovers Apple battery hack