Get the App
SLTechnology News&Howtos  ›  IT Information  › 

New Bluetooth vulnerability exposed: dating back to 2012, attackers can remotely take over devices

Shulou Source: shulou.com Published: 2023-12-24 09:56:49 09月23日 Update

CTOnews.com December 8, SkySafe researcher Marc Newlin released a GitHub blog post on December 6, revealing a high-risk Bluetooth vulnerability that affects Android, iOS, Linux and macOS devices.

The vulnerability tracking number, CVE-2023-45866, is an identity bypass vulnerability that dates back to 2012, which allows attackers to trick the Bluetooth host state without user confirmation, pairing fake keyboards, and injecting attacks to execute code as victims.

Newlin said that in the Bluetooth specification, the underlying pairing mechanism is unauthenticated and can be exploited by attackers. He said the full details of the vulnerability and proof-of-concept scripts would be publicly demonstrated at subsequent meetings.

Emily Phelps (Emily Phelps), director of Cyware, said attackers could use the vulnerability to remotely control the victim's device without authentication, depending on the system, downloading applications, sending messages or running commands.

CTOnews.com previously reported that Google's December Android security update had fixed the CVE-2023-45866 vulnerability. In addition, for more detailed information about the vulnerability, you can visit GitHub blog posts.

Related readings:

"Google December update fixes a" key "vulnerability: arbitrary code can be executed remotely without user interaction"

Tags: Vulnerabilities attacks identities attackers Bluetooth authentication devices codes victims situations unpassed messages users Android updates security spoofing hosts conferences information Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno NVidia Apple Redmi Huawei MySQL