New iPhone Wi‑Fi Crash: The %SecretClub%power SSID Vulnerability Explained

Security researcher Carl Schou has uncovered a new iPhone Wi‑Fi vulnerability where connecting to a network named “%SecretClub%power” crashes the device’s Wi‑Fi, cannot be fixed by resetting network settings, and may require a full data wipe, highlighting iOS’s flawed percent‑sign parsing.

Programmer DD
Programmer DD
Programmer DD
New iPhone Wi‑Fi Crash: The %SecretClub%power SSID Vulnerability Explained

Earlier we reported an Apple Wi‑Fi vulnerability where setting the network name to “%p%s%s%s%s%n” caused iPhone Wi‑Fi to crash, requiring a network‑settings reset to recover.

Security researcher Carl Schou recently disclosed a more severe flaw: connecting to a Wi‑Fi network named “%SecretClub%power” renders the iPhone’s Wi‑Fi unusable, and even resetting network settings does not help; the only remedy is a full data wipe.

The issue stems from iOS’s input‑parsing logic, which mistakenly treats characters following a percent sign as commands rather than plain text, leading to the Wi‑Fi malfunction.

Users who tested the bug reported that devices running iOS 15 Public Beta 1 were immediately affected, while an iPhone 11 Pro Max on iOS 14.6 showed no abnormal behavior.

Because the exact trigger conditions remain unclear, it is advisable to avoid connecting to Wi‑Fi networks whose SSID begins with a percent sign.

For reference, the following images illustrate the vulnerable SSIDs and test results.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

iOSWiFiApple
Programmer DD
Written by

Programmer DD

A tinkering programmer and author of "Spring Cloud Microservices in Action"

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.