Researchers reported AirSnitch, a set of attack techniques that bypass Wi‑Fi client isolation—a common router/access point feature intended to prevent devices on the same network (e.g., guest Wi‑Fi) from communicating directly. The work indicates the issue is not a simple “Wi‑Fi encryption is broken” narrative; rather, an attacker who is already connected to the network can impersonate other devices and intercept or manipulate traffic that isolation controls were expected to block, undermining assumptions used in home, office, and enterprise deployments.
The described methods enable man-in-the-middle, traffic injection, and data interception against both wireless and wired devices, leveraging weaknesses across areas such as group key handling and network forwarding/routing behavior. Reported techniques include abuse of shared group keys, gateway bouncing, port stealing via MAC spoofing, and broadcast reflection; testing found all evaluated routers were vulnerable to at least one technique, with potential follow-on impacts such as cookie theft, DNS poisoning, and broader session compromise. Recommended mitigations emphasize treating client isolation as insufficient as a primary boundary and prioritizing network segmentation and strong end-to-end encryption, alongside improvements to group key management.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Subsequent technical commentary described AirSnitch as exploiting Layer 1 and Layer 2 behaviors and failures to bind client identity consistently across layers and SSIDs. This analysis emphasized that attackers could gain a full bidirectional machine-in-the-middle position on the same SSID, a different SSID, or another network segment connected to the same access point.
HKCERT published a security bulletin warning that the AirSnitch attack could cause sensitive information disclosure and denial-of-service conditions in Wi-Fi environments. The advisory marked an official security-notice response to the newly disclosed attack class.
The AirSnitch research found every router tested was vulnerable to at least one technique, including shared group key abuse, gateway bouncing, port stealing via MAC spoofing, and broadcast reflection. The disclosure highlighted that both wireless and wired devices on the same network could be affected and recommended stronger segmentation, end-to-end encryption, and improved group key management.
Researchers from the University of California, Riverside reported fundamental weaknesses in Wi-Fi Client Isolation and described bypass techniques collectively named AirSnitch. The techniques allow indirectly communicating with supposedly isolated devices and can enable traffic injection, interception, and man-in-the-middle attacks across home, enterprise, and university networks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
kaspersky.com
Open sourceschneier.com
Open sourcehkcert.org
Open sourcevulnu.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.