• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - New vulnerability allows hackers to forge trusted Bluetooth devices to invade devices. Please turn off Bluetooth when not using it

New vulnerability allows hackers to forge trusted Bluetooth devices to invade devices. Please turn off Bluetooth when not using it

Claire by Claire
May 20, 2020 - Updated on August 4, 2026
in Anti-Virus Software and Internet Security

Bluetooth is now a basic equipment for all mobile phones, laptops and tablets. Due to the elimination of headphone jacks, Bluetooth headphones have almost become a peripheral for everyone, not to mention smart bracelets, watches, etc. that all use Bluetooth as a connection method. Because of its ubiquity, people have begun to forget its existence. Foreign research units have discovered a new Bluetooth vulnerability that allows attackers to disguise themselves as trusted Bluetooth devices and use this to launch Bluetooth impersonation attacks (BIAS) on users’ devices.

New vulnerability allows hackers to forge trusted Bluetooth devices to invade devices. Please turn off Bluetooth when not using it

With foreign media Appleinsider reported that when two Bluetooth devices are paired, they will reach a consensus on the connection key, so that they do not need to pair again when they reconnect with each other in the future. A group of scholars at the Ecole Polytechnique Fédérale de Lausanne in Switzerland discovered that a new BIAS attack exploits a vulnerability in how Bluetooth devices handle long connections, deceiving Bluetooth devices that have been paired in the past to successfully pass authentication without knowing the connection key.

More specifically, the flaw manifests itself when an attacking device is disguised as a trusted device that only supports one-party authentication. The security settings of Bluetooth are not high. The user’s device is usually used to verify whether the link is a valid device. However, through this role switching method, an attacker can deceive the authentication mechanism and easily establish a secure connection with the user’s device. An attacker can use it in conjunction with other Bluetooth attacks, such as Bluetooth Key Negotiation (KNOB), to compromise a device operating in secure authentication mode. Once a BIAS attack is successful, the attacking device can be used to conduct other continuous attacks, including accessing data sent over Bluetooth and even controlling the functionality of a previously paired device. Because Bluetooth connections typically do not require explicit user cross-authentication, BIAS and KNOB attacks can be carried out covertly without the user’s knowledge.

This vulnerability only affects Bluetooth Basic Rate/Enhanced Data Rate Classic Bluetooth, but can still affect relatively new Apple devices, including iPhone 8 and earlier, 2017 MacBook and older, and 2018 iPad and older. To carry out an attack, a hacker must be within Bluetooth range of the target device and know the Bluetooth addresses of previously paired devices. For a skilled attacker, these Bluetooth addresses are relatively easy to find, even if they are randomly varied.

Researchers have issued a warning to the Bluetooth Special Interest Group (SIG),The group has updated the Bluetooth core specification to mitigate the vulnerability, manufacturers such as Apple and Samsung are likely to release firmware or software updates with this fix in the near future. To reduce your vulnerability to attacks, you can turn off Bluetooth when not using it, or ensure that there are no connection keys on each device you paired it with in the past by manually unpairing it.

◎Data source:Appleinsider 

Source: KOCPC Chinese

Tags: BluetoothloopholessecuritySecurity vulnerability

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology