Sharing the details in a blog post, the researchers explained that a potential attacker may hack the respective fast charger and rewrite its firmware code to change the voltage delivered.
While most chargers deliver 5V power as a standard, the hacking attack may cause them to deliver up to 20V. This excessive voltage may damage the hardware of the power receiving equipment, even triggering a burn.
Such manipulative voltage change may also accompany a miscommunication between the charger and the other equipment. While the hacked charger may communicate a 5V power transmission, in effect, it would deliver more voltage.
To conduct the attack, an attacker may simply hack the charger’s firmware by connecting a special device to it that mimics a phone. Then, whenever any device is connected to the hacked charger, it would be damaged due to power overload.
In their study, the researchers tested 35 of the 234 available fast-charging devices in the market. From these 35, they found 18 belonging to 8 different brands vulnerable to BadPower. From these 18, 11 chargers could fall prey to BadPower when attacked through digital terminals.
The researchers have shared the details of the exploit and a PoC video in their post.
Whereas, for the future, the vendors may consider including the following checks in the chargers’ design.