Join our Newsletter — 33% off our NHI Course
Threats, Abuse & Incident Response

KRACK

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Threats, Abuse & Incident Response

KRACK is a family of Wi-Fi attack techniques that target weaknesses in the WPA2 handshake. The issue can allow decryption, replay, or injection of traffic under certain conditions, but exploitation typically requires close proximity and interaction with individual clients rather than a blanket compromise of every wireless device.

What KRACK Means in Practice

KRACK is not a single bug in one device, but a class of attacks that abuse how WPA2 key handshake state is handled. The practical lesson is that wireless security can fail even when the password is strong, if the protocol state machine is manipulated.

That makes KRACK a protocol-level weakness rather than a simple credential theft event. The attack surface is the handshake logic itself, so the outcome depends on client behavior, retransmission handling, and whether an implementation correctly installs and protects session keys.

How KRACK Works

KRACK targets the WPA2 four-way handshake, which is designed to prove that both sides possess the shared secret and to derive fresh encryption keys for the session. By replaying or manipulating handshake messages, an attacker can induce a victim to reinstall an already-in-use key.

Key reinstallation can reset packet numbers and nonce values, which undermines the protections that keep encrypted Wi-Fi traffic unique. Once that state is disturbed, confidentiality and integrity can weaken in different ways depending on the cipher suite and the client implementation.

The attack does not usually mean an attacker learns the Wi-Fi password. Instead, it exploits a logic flaw in the connection setup, which is why patched software and correctly hardened clients matter as much as strong wireless credentials.

Why the Exposure Matters

KRACK can expose traffic that users assume is protected by WPA2, especially when clients fail to defend against key reinstallations. That can create confidentiality loss, packet injection opportunities, and traffic manipulation on affected links.

The practical severity varies by device type, operating system, and patch status. Some implementations were affected more than others, and some ciphers or mitigation features reduce the impact, but the broad lesson is that wireless encryption is only as strong as its handshake implementation.

For readers mapping KRACK to broader security controls, NIST SP 800-53 Rev 5 Security and Privacy Controls is a useful reference point for access control, authentication, configuration management, and integrity safeguards that help limit protocol abuse.

Defensive Takeaways for Wireless Environments

KRACK is a reminder that patching wireless clients and access points is not optional housekeeping, it is part of keeping encryption trustworthy. Even where enterprise Wi-Fi uses strong authentication and modern credentials, an unpatched endpoint can remain exposed to handshake abuse.

Defenders should treat this as an implementation assurance issue: verify vendor updates, confirm client patch coverage, and validate that wireless configurations support the strongest available protections. For broader hardening context, CIS Benchmarks are a practical baseline for reducing configuration weakness across endpoints and network-connected systems.

Where organizations are reviewing wireless security as part of a wider control set, NIST Cybersecurity Framework 2.0 provides a structured way to align governance, protection, detection, and recovery activities around exposure like this.

Risk and Threat Considerations

KRACK matters because it turns a trusted encryption handshake into a point of failure. If a nearby attacker can force key reuse or state rollback, encrypted Wi-Fi traffic may become readable, replayable, or injectable even when users believe the network is protected.

Failure mechanism: The attacker abuses handshake retransmission and key reinstall behavior, which can reset internal counters and weaken the protections that WPA2 relies on to preserve session confidentiality and integrity.

Impact: Affected clients may leak traffic content, accept replayed packets, or process injected frames, creating exposure for sensitive data and potentially enabling follow-on attacks against the connected device or user session.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-17 — Remote AccessKRACK affects wireless remote access sessions and their trust boundaries.
IA-2 — Identification and Authentication (Organizational Users)WPA2 handshakes establish authenticated access to the wireless network.
CM-6 — Configuration SettingsKRACK exposure depends on endpoint and access-point configuration and patch state.
Recommendation — Harden wireless remote access and validate session protections on all clients. Verify that wireless authentication and reauthentication paths are patched and enforced. Standardize and verify secure wireless configurations and vendor updates.
CIS Controls v8CIS-4 — Secure Configuration of Enterprise Assets and SoftwareKRACK mitigation depends on hardened wireless and endpoint configuration.
CIS-10 — Malware DefensesWireless traffic injection can support follow-on malicious activity on endpoints.
Recommendation — Apply secure configuration baselines and keep wireless software updated. Use layered endpoint defenses to reduce the impact of injected traffic.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org