Explorer

All Devices Since 2014 Can Be Hijacked, Says New Discovered Bluetooth Security Flaw

Recently identified security flaws in Bluetooth security can enable attackers to take control of connections across devices utilising Bluetooth versions 4.2 to 5.4, including devices from late 2014 to the present date.

Recently identified security flaws in Bluetooth security can enable attackers to take control of connections across devices utilising Bluetooth versions 4.2 to 5.4, including devices from late 2014 to the present date. Notably, Apple devices are particularly vulnerable, with AirDrop posing a heightened risk. These vulnerabilities manifest through six distinct exploits, facilitating both device impersonation and man-in-the-middle attacks, says a report by Bleeping Computer, citing research by expert Daniele Antonioli from Eurecom.

According to Eurecom researchers, six novel attacks collectively referred to as 'BLUFFS', he been made. These attacks can compromise the confidentiality of Bluetooth sessions, thus, enabling device impersonation and facilitating man-in-the-middle (MitM) attacks.

The attacker, within the Bluetooth range, can subsequently discern or modify these keys to decode or manipulate the data, necessitating the attacker to pose as one of the devices engaged in data sharing.

The flaw impacts a wide range of devices, including laptops, PCs, smartphones, tablets, and more, as all Bluetooth-enabled devices are vulnerable to at least three out of the six BLUFFS attacks, according to the research paper.

How To Stay Safe?

A recommended practice is to keep Bluetooth disabled on mobile devices unless necessary. This involves turning it on when using Bluetooth headphones and turning it off afterward.

These security flaws aren't tied to particular hardware or software configurations; however, they are inherent to the architecture, impacting Bluetooth at a foundational level. Antonioli, the discoverer of the attacks, elaborates that BLUFFS leverages two previously undiscovered flaws in the Bluetooth standard concerning the derivation of session keys for decrypting exchanged data.

The researchers have made and shared a toolkit on GitHub that demonstrates the effectiveness of BLUFFS, the report further noted. It includes a Python script to test the attacks, the ARM patches, the parser, and the PCAP samples captured during their tests.

Top Headlines

Jharkhand Protest: State Govt Accepts Key Demands, Cancels ACF, 14th JPSC PT Exams
Jharkhand Protest: State Govt Accepts Key Demands, Cancels ACF, 14th JPSC PT Exams
Netanyahu Rejects 'Great Friend' Trump’s 15-Point Gaza Plan, Says No Israeli Pullout Without Hamas Disarmament
'I Know How To Stand My Ground': Netanyahu Rejects 'Great Friend' Trump’s Gaza Plan
'We Could Have All Been Killed': Mamata’s Car Attacked With Stones, Mud Smeared; ‘Thief, Thief’ Chants Raised | WATCH
Mamata’s Car Attacked With Stones, Mud Smeared; ‘Thief, Thief’ Chants Raised | WATCH
Laser Beam Hits Pilot, Malaysia Airlines Flight Forced To Circle Before Kolkata Landing
Malaysia Airlines Flight With 159 Onboard Hit By Laser Beam Near Kolkata Airport

Videos

Jharkhand: Jharkhand Government Holds Third Round of Talks With Student Groups Ahead of Assembly Gherao
Iran: New Video of Iran’s Mustafa Khamenei Raises Fresh Questions Over His Health
Uttar Pradesh Politics: Yogi Government Launches ‘Mission Gen-Z’ Ahead of 2027 UP Assembly Elections
Aviation: Air India Turbulence Incident Under DGCA Probe, Captain’s Drug Test Reportedly Being Examined
Jharkhand Politics: BJP Claims Rahul Gandhi Pressuring Hemant Soren Over JPSC-JSSC Row

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget