A potential security issue has been discovered by cybersecurity researchers that has the capability to affect more than one billion devices.
According to researchers at the cybersecurity firm Tarlogic, a hidden command has been foundcoded into a bluetooth chip installed in devices around the world. This secret functionality can be weaponized by bad actors and, according to the researchers, used as an exploit into these devices.
Using these commands, hackers could impersonate a trusted device and then connect to smartphones, computers, and other devices in order to access information stored on them. Bad actors can continue to utilize their connection to the device to essentially spy on users.
The bluetooth chip is called ESP32 and is manufactured by the China-based company Espressif. According to researchers, the ESP32 is "a microcontroller that enables WiFi and Bluetooth connection." In 2023, Espressif reported that one billion units of its ESP32 chip had been sold globally. Millions of IoT devices like smart appliances utilize this particular ESP32 chip.
Tarlogic researchers say that this hidden command could be exploited, which would allow "hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls." Tarlogic says that these commands are not publicly documented by Espressif.
Researchers with Tarlogic developed a new Bluetooth driver tool in order to aid in Bluetooth-related security research, which enabled the security firm to discover a total of 29 hidden functionalities that could be exploited to impersonate known devices and access confidential information stored on a device.
According to Tarlogic, Espressif sells these bluetooth chips for roughly $2, which explains why so many devices utilize the component over higher costing options.
As BleepingComputerreports, the issue is being tracked as CVE-2025-27840.
Copyright © 2023 Powered by
Secret commands found in Bluetooth chip used in a billion devices-口沸目赤网
sitemap
文章
51
浏览
3
获赞
1
These coronavirus trackers can help you sort through the info overload
If you're like me, the daily barrage of information about the progress of the coronavirus pandemic cJudge won't let 'Fortnite' back into App Store as Apple fight crawls on
The battle royale between Epic Games and Apple is far from over. The ongoing debate over whether ForWe're fracking the hell out of the U.S. Can Jay Inslee stop it?
U.S. Route 285, cutting through the Texas-New Mexico border, is perilous.Lines of speeding trucks luTikTok introduces stricter privacy rules for its youngest users
TikTok, the social media site known for its popularity among youth, is making its youngest users' acFitbit has developed a ventilator to help COVID
Just like Dyson and NASA before it, Fitbit has now designed a ventilator in response to the coronaviTikTok is reportedly testing longer videos
Longer videos are coming to some users on TikTok.The company is reportedly letting some users createFacebook reveals its impotence as Trump sows confusion about voting twice
In the friendly face-off between Mark Zuckerberg and Donald Trump, Zuckerberg just blinked. Again.OnAre Passwords Dead? What Are Passkeys, and Why Everyone's Talking About Them
We've all been there. You try to log into your bank account with your username and password only toInside the online communities where straight guys help other straight guys get off
May is National Masturbation Month, and we're celebrating withFeeling Yourself, a series exploring tChinese drone company DJI added to U.S. government blacklist
The U.S. Department of Commerce announced in a conference call on Friday morning that DJI, a big nam5 important details you may have missed from Apple's November event
Apple's "One more thing" event is behind us, and I bet you're confused. In some ways, Apple has simpDouglas, the latest step toward realistic AI, is unsettling
UPDATE: Nov. 22, 2020, 11:48 a.m. EST This story was updated to more accurately reflect how Douglas'The first photos of Harry and Meghan's new baby are finally here
Well, the wait is finally over. The Duke and Duchess of Sussex have put us out of our misery and revCrypto wallet MetaMask finally launches on iOS and Android, and it supports Apple Pay
If you've interacted with cryptocurrencies in the past couple of years, there's a good chance you'veHow do you weigh a massive whale?
Dead whales, stranded and decaying on beaches, can sometimes be weighed. But weighing a live whale i