Surveilling the Masses with Wi-Fi-Based Positioning Systems
Erik C. Rye, Dave Levin
Abstract
Wi-Fi-based Positioning Systems (WPSes) are used by modern mobile devices to learn their position using nearby Wi-Fi access points as landmarks. In this work, we show that Apple’s WPS can be abused to create a privacy threat on a global scale. We present an attack that allows an unprivileged attacker to amass a worldwide snapshot of Wi-Fi BSSID geolocations in only a matter of days. Our attack makes few assumptions, merely exploiting the fact that there are relatively few dense regions of allocated MAC address space. Applying this technique over the course of a year, we learned the precise locations of over 2 billion BSSIDs around the world.The privacy implications of such massive datasets become more stark when taken longitudinally, allowing the attacker to track devices’ movements. While most Wi-Fi access points do not move for long periods of time, many devices—like compact travel routers—are specifically designed to be mobile.We present several case studies that demonstrate the types of attacks on privacy that Apple’s WPS enables: We track devices moving in and out of war zones (specifically Ukraine and Gaza), the effects of natural disasters (specifically the fires in Maui), and the possibility of targeted individual tracking by proxy—all by remotely geolocating wireless access points.We provide recommendations to WPS operators and Wi-Fi access point manufacturers to enhance the privacy of hundreds of millions of users worldwide. Finally, we detail our efforts at responsibly disclosing this privacy vulnerability, and outline some mitigations that Apple and Wi-Fi access point manufacturers have implemented both independently and as a result of our work.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a7bfa6f6-caeb-4858-a76a-66dfdcc6efd8Cited by top-tier papers3
- WILD Attack: Stealthy Undermining of Wi-Fi-Based Geolocation Through Remote Crowdsourced Data InjectionChangjia Zhu, Xiao Han, Parush Gera, Zhuo Lu et al.USENIX Security 2026
- Analyzing the iOS Local Network Permission from a Technical and User PerspectiveDavid Schmidt, Alexander Ponticello, Magdalena Steinböck, Katharina Krombholz et al.S&P 2025
- Tracking You from a Thousand Miles Away! Turning a Bluetooth Device into an Apple AirTag Without Root PrivilegesJunming Chen, Xiaoyue Ma, Lannan Luo, Qiang ZengUSENIX Security 2025
Builds on3
- Location Heartbleeding: The Rise of Wi-Fi Spoofing Attack Via Geolocation APIXiao Han, Junjie Xiong, Wenbo Shen, Zhuo Lu et al.CCS 2022 · 7 citations
- IPvSeeYou: Exploiting Leaked Identifiers in IPv6 for Street-Level GeolocationErik C. Rye, Robert BeverlyS&P 2023
- Blue Is the New Black (Market): Privacy Leaks and Re-Victimization from Police-Auctioned CellphonesRichard Roberts, Julio Poveda, Raley Roberts, Dave LevinS&P 2023
Related papers
- Non-cooperative wi-fi localization & its privacy implicationsAli Abedi, Deepak VasishtMobiCom 2022 · 30 citations
- A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct LinkMilan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich et al.USENIX Security 2019 · 59 citations
- Disrupting Continuity of Apple's Wireless Ecosystem Security: New Tracking, DoS, and MitM Attacks on iOS and macOS Through Bluetooth Low Energy, AWDL, and Wi-FiMilan Stute, Alexander Heinrich, Jannik Lorenz, Matthias HollickUSENIX Security 2021 · 31 citations
- A Systematic Threat Analysis and Practical Attacks on Automated Frequency Coordination SystemsYilu Dong, Tianchang Yang, Arupjyoti Bhuyan, Syed Rafiul HussainNSDI 2026
- Et Tu Alexa? When Commodity WiFi Devices Turn into Adversarial Motion SensorsYanzi Zhu, Zhujun Xiao, Yuxin Chen, Zhijing Li et al.NDSS 2020
