CAREFUL! Bluetooth failure can expose your data to criminals 1

CAREFUL! Bluetooth failure can expose your data to criminals

Eurecom researchers recently identified two serious security flaws that affect all versions of bluetooth from 4.2.

The vulnerabilities, called “BLUFFS”, allow the interception of Bluetooth connections, compromising the confidentiality of sessions and enabling attacks man-in-the-middle (MitM) and device counterfeiting.

Vulnerabilities in Bluetooth connections

These vulnerabilities impact devices using Bluetooth 4.2 up to version 5.4, including iPhonesAndroid smartphones, tablets and computers.

Bluetooth 4.2, released in December 2014, makes the scope of those affected extensive, raising significant concerns about the security of wireless communication.

The researchers, in turn, explained that the techniques exploit four flaws in the session key derivation process, forcing the creation of shorter, weaker and more accessible keys.

This essentially induces devices to use security keys simpler, making them vulnerable to brute force attacks.

Attackers can exploit these flaws to hijack Bluetooth connections in two main ways: by pretending to be the target device and intercepting user-sent data, or by acting as an intermediary between two devices.

CAREFUL! Bluetooth failure can expose your data to criminals 2

Bluetooth security flaws leave your device vulnerable – Image: Canva Pro/Reproduction

To date, there are no specific measures users can take to protect themselves against these vulnerabilities other than turning off Bluetooth.

Now, the onus is on manufacturers to develop updates that fix these security holes. However, it remains uncertain whether the updates will be able to patch already released devices.

The Bluetooth SIG, the group responsible for developing Bluetooth, suggested that manufacturers strengthen connection security by making the use of more complex keys standard.

This measure could be crucial to prevent future attacks and protect users of Bluetooth devices.

Additionally, it is important to note that the connection Bluetooth Low Energy (BLE) has also recently been identified as vulnerable to attacks, which highlights the importance of firmware updates to maintain communication security wireless.

Support our work ❤️

If you enjoyed this article, consider leaving a tip to help us keep publishing great content.

Secure payment on PayPal
Moyens I/O Staff is a team of expert writers passionate about technology, innovation, and digital trends. With strong expertise in AI, mobile apps, gaming, and digital culture, we produce accurate, verified, and valuable content. Our mission: to provide reliable and clear information to help you navigate the ever-evolving digital world. Discover what our readers say on Trustpilot.