Original Research 7 min read

Public Wi-Fi Security Risks: What the Research Actually Shows

What research says about public Wi-Fi risk: evil twins, KRACK, FragAttacks, SSID confusion and TunnelVision, how HTTPS changed things, and what still matters.

Public Wi-Fi Security Risks: What the Research Actually Shows

Key Findings

  • HTTPS now covers 95 to 99% of Chrome navigations, up from 30 to 45% in 2015, which removes most of the passive-snooping risk that made open Wi-Fi notorious.
  • Every Wi-Fi product tested in the 2021 FragAttacks research was vulnerable to at least one of its flaws, and three of those design flaws date back to Wi-Fi's 1997 standard.
  • The 2024 SSID confusion flaw (CVE-2023-52424) affected every device its researchers tested and can trick some VPN apps into switching themselves off.
  • In November 2025, an Australian man was jailed for seven years and four months after running fake 'evil twin' Wi-Fi portals at airports and on flights to steal login details.

Public Wi-Fi is much safer than its reputation suggests, mainly because 95 to 99% of web traffic in Chrome now uses HTTPS, which encrypts your data even on an open network. The risks that remain are real but narrower: fake “evil twin” hotspots and login portals that trick you into typing your passwords, unpatched devices hit by Wi-Fi protocol flaws such as FragAttacks, and newer attacks that can switch off or bypass a VPN without warning. Keeping devices updated and being careful about what you type into a Wi-Fi login page prevents most of them.

How HTTPS changed the public Wi-Fi threat

The classic warning, that anyone on the same café network can read your traffic, comes from a time when most websites were unencrypted, which is no longer the case.

According to Google, HTTPS accounted for only 30 to 45% of Chrome navigations in 2015. Since about 2020, it has been in the 95 to 99% range. Excluding private sites, the share is about 98% on Windows and above 99% on Android and Mac (Google, 2025). Chrome began turning on “Always Use Secure Connections” by default for Enhanced Safe Browsing users with version 147 in April 2026, and planned to turn it on for everyone with version 154 in October 2026.

The FTC’s consumer advice reflects this shift. It says that, thanks to widespread encryption, “connecting through a public Wi-Fi network is usually safe” (FTC, 2023). The agency still warns that scammers can build fake sites that also show a padlock: HTTPS protects your data on the way to a site, but it does not tell you whether the site is honest.

Documented Wi-Fi attacks

AttackYear disclosedWhat it doesWho is affectedStatusSource
Evil twin / fake captive portalLong-standing; prosecuted in 2024-2025Fake hotspot copies a trusted network name and shows a login page that harvests credentialsAnyone who joins and types logins into the portalNo patch possible; user caution requiredAFP, 2025
KRACK (CVE-2017-13077 to CVE-2017-13088)2017Forces reuse of encryption keys in the WPA2 handshake so traffic can be decryptedWPA2 devices; Android 6.0+ and Linux could be forced to use an all-zero keyPatched by vendors; changing the Wi-Fi password does not helpVanhoef, 2017
FragAttacks (CVE-2020-24586/24587/24588 plus nine implementation CVEs)2021Abuses how Wi-Fi fragments and combines frames to inject or steal dataEvery product tested had at least one flawMostly patched; old routers and IoT devices often are notVanhoef, 2021
SSID confusion (CVE-2023-52424)2024Tricks a device into joining a different network while showing the trusted nameAll tested devices; affects WEP, WPA3 SAE-loop, 802.1X/EAP (enterprise), mesh and FILSStandard updated; mitigations rolling outGollier & Vanhoef, 2024
TunnelVision (CVE-2024-3661)2024A rogue DHCP server pushes routes that send traffic outside the VPN tunnelRouting-based VPNs on Windows, Linux, iOS, macOS; not AndroidMitigations vary by VPN clientLeviathan Security, 2024

Evil twins and fake login pages

The best-documented real-world harm from public Wi-Fi is social engineering. In a case brought by the Australian Federal Police, a man used a portable device to listen for the network names that phones and laptops search for, then instantly created matching networks. People who joined at airports in Perth, Melbourne and Adelaide, or on domestic flights, saw a page asking them to log in with an email or social media account, and those credentials were saved to his device. He was sentenced in November 2025 to seven years and four months in prison (AFP, 2025).

HTTPS does nothing to stop this, because the victim is typing a password into the attacker’s own page. The protection is behavioral: a legitimate hotspot has no reason to ask for your Google, Facebook or email password.

KRACK (2017)

Researcher Mathy Vanhoef showed that an attacker within radio range could manipulate the WPA2 handshake and force devices to reuse keys, making traffic readable. Android 6.0+ and Linux devices were hit hardest because they could be tricked into using an all-zero key (Vanhoef, 2017). Vendors released patches years ago, and both devices and access points needed updating. Vanhoef also noted that HTTPS had been bypassed in some apps, so it should not be the only layer of protection.

FragAttacks (2021)

FragAttacks covered three design flaws in the Wi-Fi standard and nine implementation bugs. The design flaws date back to the original 1997 standard, and every Wi-Fi product the researcher tested was affected by at least one of them (Vanhoef, 2021). The design flaws are hard to exploit in practice, but some implementation bugs were described as trivial to exploit. The biggest remaining risk is unpatched routers and smart-home devices, since up-to-date phones have the fixes.

SSID confusion (2024)

KU Leuven researchers showed that the name of a protected Wi-Fi network is not always authenticated. A machine-in-the-middle can make a device join “WrongNet” while it displays “TrustedNet.” This works when two networks share credentials, for example separate 2.4 GHz and 5 GHz networks, or enterprise networks like eduroam. All tested devices were vulnerable (Gollier & Vanhoef, 2024). By design, WPA2-Personal and WPA3 using the newer SAE-const method are not affected.

For VPN users the flaw has a direct consequence. Some VPN apps can turn themselves off automatically on “trusted” networks that they identify only by name, so a spoofed name can disable the VPN.

TunnelVision (2024)

Leviathan Security showed that an attacker who controls the DHCP server on a local network, such as a rogue café hotspot, can use DHCP option 121 to inject routes that send chosen traffic outside the VPN tunnel. The VPN still appears connected, so kill switches don’t trigger (Leviathan Security, 2024). Android is not affected because it ignores that DHCP option.

What’s overstated and what still matters

Two common warnings overstate the risk:

  • “Anyone on the network can read your passwords.” With HTTPS on almost every site, a passive eavesdropper mostly sees which domains you visit, not your passwords or messages.
  • “Never do banking on public Wi-Fi.” Banking apps and sites use HTTPS. The danger comes from a fake login page or a compromised device rather than the café network itself.

These risks are still real:

  • Credential phishing through captive portals and evil twins, as the Australian case shows.
  • Unpatched devices, because protocol flaws like FragAttacks matter for old laptops, routers and IoT devices that never get updates.
  • Metadata exposure. Hotspot operators and attackers can still see domain names and timing, and in some cases DNS lookups.
  • Hostile local networks that target VPNs, as TunnelVision and SSID confusion show.

Security agencies are still cautious, especially for work devices. NSA guidance for government and defense teleworkers recommends a personal or corporate mobile hotspot over public Wi-Fi. If public Wi-Fi is unavoidable, it recommends a VPN, and it advises turning off Wi-Fi, Bluetooth and NFC when not in use (BleepingComputer, 2021).

On the network side, Wi-Fi Enhanced Open (based on Opportunistic Wireless Encryption) encrypts each user’s connection on password-free networks. It protects against passive eavesdropping, but it does not prove that the network is the one it claims to be (Wi-Fi Alliance, 2018).

What this means for you

  1. Never enter account passwords into a Wi-Fi login page. A hotspot may legitimately ask you to accept terms or enter a room number, but it has no reason to ask for your email or social media password.
  2. Keep everything updated. KRACK and FragAttacks are mostly solved problems on patched devices. Replace or update routers and smart devices that no longer get firmware updates.
  3. Turn off auto-join for open networks and forget hotspots you no longer use, since evil-twin tools exploit devices that automatically reconnect to known names.
  4. Watch for browser certificate warnings and do not click through them. Turn on your browser’s HTTPS-only mode if it isn’t already the default.
  5. Use your phone’s hotspot for sensitive work. It is the simplest way to avoid a network you don’t control.
  6. If you use a VPN, don’t rely on “disable on trusted networks” settings that recognize networks only by name, and keep the VPN client updated against attacks like TunnelVision.
  7. Turn on two-factor authentication or passkeys, so a password captured by a fake portal isn’t enough to take over your account.

Methodology

Attack details and CVE numbers come from the researchers’ own publications and disclosure sites: KRACK, FragAttacks, the WiSec 2024 SSID confusion paper and Leviathan Security’s TunnelVision disclosure. HTTPS adoption figures are Google’s own. Guidance comes from the FTC and the NSA (the latter via BleepingComputer’s report on the NSA information sheet), the Enhanced Open details from the Wi-Fi Alliance’s announcement, and the evil twin case from the Australian Federal Police’s announcement.

There is no reliable public dataset on how often public Wi-Fi attacks happen. Criminal cases like the Australian one show the attacks are real but not how common they are. The protocol attacks were demonstrated in controlled settings, and whether they can be exploited in practice depends on patch levels, network setup and how close the attacker is. The HTTPS figures cover Chrome navigations only and do not include traffic from other apps. Commercial “survey” figures about how many people use public Wi-Fi unsafely are left out because we could not trace them to a published methodology.

Sources

  1. Key Reinstallation Attacks: Breaking WPA2 by forcing nonce reuse (KRACK) — Mathy Vanhoef, KU Leuven, 2017
  2. FragAttacks: Fragmentation and aggregation attacks — Mathy Vanhoef, 2021-05-11
  3. SSID Confusion: Making Wi-Fi Clients Connect to the Wrong Network (WiSec '24) — Héloïse Gollier and Mathy Vanhoef, KU Leuven, 2024-05
  4. TunnelVision (CVE-2024-3661): How Attackers Can Decloak Routing-Based VPNs — Leviathan Security Group, 2024-05-06
  5. HTTPS by default — Google Security Blog, 2025-10-28
  6. WA man jailed for stealing intimate material and using 'evil twin' WiFi networks — Australian Federal Police, 2025-11
  7. Are Public Wi-Fi Networks Safe? What You Need To Know — Federal Trade Commission, 2023-02
  8. NSA shares guidance on how to secure your wireless devices — BleepingComputer (on NSA guidance), 2021-07-29
  9. Wi-Fi CERTIFIED Enhanced Open delivers data protection in open Wi-Fi networks — Wi-Fi Alliance, 2018-06-05
Cite this research: PhantomGuide Research Team, “Public Wi-Fi Security Risks: What the Research Actually Shows”, PhantomGuide, 2026-10-01, https://phantomguide.com/research/public-wifi-risks/

More Research