Radio Frequency Identification (RFID) is one of the most promising authentication technologies in pervasive computing. Besides identification, the RFID also offers mutual authentication to IoTs (Internet of Things) terminal devices and manages the access control of IoT networks. To decrease the overall cost of the IoT sensors (RFID tags), Ultralightweight Mutual Authentication Protocols (UMAPs) have been proposed. These UMAPs incorporate simple bitwise logical operators (e.g. XOR, AND, OR, Modulo 2 addition, etc.) and extremely low-cost non-triangular primitives in their designs to ensure confi-dentiality, authentication, and integrity. In this paper, we have performed a cryptanalysis of the recently proposed UMAP: Ultralightweight RFID Authentication Protocol (URAP). We have exploited the weak structure of URAP design and identified a desynchronization attack. The proposed attack requires only two (2) sessions to desynchronize the IoT sensor from its network fully. We have also discussed other design flaws of the protocol structure which can lead towards several full disclosure attacks.