Researchers disclosed two major Wi‑Fi weaknesses that undermined protections widely assumed to be provided by WPA2. The KRACK attack, discovered by Mathy Vanhoef, abused the WPA2 four-way handshake to force key reinstallation, allowing a nearby attacker to replay, decrypt, or forge traffic and in some cases hijack TCP sessions or inject malicious content. Because the flaw targeted the protocol rather than a single product, it affected home, office, and public Wi‑Fi environments across many vendors and platforms, with Android 6.0 and Linux described as especially exposed due to implementations that could reset encryption keys to all zeros; Windows and iOS were considered harder to exploit. Security agencies and vendors, including CERT/CC, NCSC, Microsoft, and Google, issued warnings and began releasing patches.
A later disclosure, KrØØk (CVE-2019-15126), showed that unpatched Broadcom and Cypress Wi‑Fi chipsets could encrypt some packets with an all-zero key after disassociation, letting nearby attackers decrypt portions of wireless traffic. ESET said the bug affected more than one billion devices, including smartphones, laptops, IoT products, routers, and access points from vendors such as Amazon, Apple, Google, Samsung, Asus, Huawei, Xiaomi, and Raspberry Pi. Although KrØØk was related to KRACK, it was a distinct flaw, and both incidents reinforced the same operational guidance: changing a Wi‑Fi password does not fix protocol or chipset weaknesses, while timely firmware and OS updates, plus relying on HTTPS, VPNs, or other end-to-end encryption for sensitive activity, materially reduce exposure.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
ESET publicly disclosed KrØØk on CVE-2019-15126, describing a Wi-Fi encryption flaw related to but distinct from KRACK. The company identified vulnerable products from vendors including Amazon, Apple, Google, Samsung, Raspberry Pi, Xiaomi, Asus, and Huawei prior to remediation.
By the time ESET published its findings, major manufacturers had already released patches for products using affected Broadcom and Cypress Wi-Fi chipsets. ESET said the issue had affected more than one billion devices across phones, laptops, IoT devices, routers, and access points before patching.
ESET discovered the KrØØk vulnerability, tracked as CVE-2019-15126, and responsibly disclosed it to Broadcom and Cypress while coordinating through ICASI. The flaw caused some devices to encrypt certain Wi-Fi packets with an all-zero key, enabling nearby decryption of portions of traffic.
Mathy Vanhoef and Frank Piessens reported updated KRACK-related attacks against WPA2/802.11, including easier exploitation of the four-way handshake and additional key reinstallation weaknesses in mechanisms such as FILS, TPK/TDLS PeerKey, and group key handling. Their research also said some early Apple macOS and iOS KRACK patches were buggy before later being fixed, and described a lower-impact bypass involving 802.11v WNM-Sleep frames.
Vendors started issuing software updates to fix vulnerable WPA2 implementations, with Microsoft already releasing patches and Google preparing updates; Linux patches were also noted as available. Guidance stressed that changing Wi-Fi passwords would not mitigate the flaw, but patching devices and routers would.
Following disclosure of KRACK, CERT/CC issued an alert and the UK's National Cyber Security Centre began reviewing or warning about the issue. Public guidance emphasized that users should not rely on Wi-Fi encryption alone for sensitive communications until patches were applied.
Researcher Mathy Vanhoef disclosed KRACK, a weakness in the WPA2 Wi-Fi protocol that lets a nearby attacker force key reinstallation and potentially replay, decrypt, or forge traffic. Because the flaw affects WPA2 itself, it impacted home, office, and public Wi-Fi networks across many vendors and platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
12 references tracked. Mallory keeps watching after this page renders.
eset.com
Open sourcedarkreading.com
Open sourcexda-developers.com
Open sourcewelivesecurity.com
Open sourcearstechnica.com
Open sourceforbes.com
Open sourcebleepingcomputer.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.