
In the wake of the BlackRock malware that was able to steal money and passwords through hundreds of apps, computer security researchers from DBAPPPSecurity have discovered a critical “zero-day” flaw in Android. The vulnerability uses the Bluetooth connection of Android smartphones and tablets to access PBAP. phonebook access profileand to the governing MAP Access to SMS.
Just like the BIAS vulnerability discovered in May 2020, this flaw, called “BlueRepli,” allows a hacker to Target any Android device via Bluetooth. It is powered by Bluetooth profiles. Normally, Bluetooth pairing is always preceded by a pairing code or authorization in the form of a Yes or No question. However, there is a third possibility called “It Just Works” also available.
The art of concealment
Concretely, Just Works is the default pairing method for most Android devices with a BLE network. When two devices are first “introduced” and paired, Just Works connection mode will reconnect them without permissionThis vulnerability is based exactly on this system.
Thanks to “BlueRepli”, a hacker can impersonate a Bluetooth-enabled device the person whose profile is saved on the target smartphone. In fact, the hacker can connect to the targeted smartphone without the user’s knowledge. We call this Bluesnarfing. Remember that the hacker should not be within Bluetooth range, i.e. more than a few meters.
Bluetooth priority target
Despite this restriction, it can be easy to spot a target, especially in a train station or airport, especially since users regularly leave their Bluetooth on since the advent of wireless headphones and connected watches. As explained by Xu Sourcell and Xin Xin, the two computer security researchers behind the “BlueRepli” discovery, this defect can cause catastrophic damage.
In fact, it is about a universal protocol, in this case Bluetooth, which means: Any Android smartphone or tablet is a potential victim. Google approved for now has not yet fixed this flaw in the operating system.. In other words, Bluetooth continues to be a gateway for hackers. Researchers advise users to be careful and stay tuned for upcoming Android security updates.
Source: Android Rookies
Support our work ❤️
If you enjoyed this article, consider leaving a tip to help us keep publishing great content.


























