Bluetooth Devices May Leak Your Secrets Due to Design Flaw

Smartphone Apps That Work With Bluetooth Devices Have a Design Flaw That Makes Them Vulnerable to Hacking, New Research Claims.

Advertisement
By Indo-Asian News Service | Updated: 15 November 2019 18:11 IST

Be it a fitness tracker, smartwatch, smart speaker or smart home assistant, the way Bluetooth devices communicate with the mobile apps leaves room for hackers to steal sensitive personal information, new research has found. An inherent design flaw makes mobile apps that work with Bluetooth Low Energy devices vulnerable to hacking, said the study described at the Association for Computing Machinery's Conference on Computer and Communications Security held in London from November 11-15.

"There is a fundamental flaw that leaves these devices vulnerable -- first when they are initially paired to a mobile app, and then again when they are operating," said Zhiqiang Lin, Associate Professor of Computer Science and Engineering at The Ohio State University in the US.

"While the magnitude of that vulnerability varies, we found it to be a consistent problem among Bluetooth low energy devices when communicating with mobile apps," Lin added.

Advertisement

Consider a wearable health and fitness tracker, smart thermostat, smart speaker or smart home assistant.

Advertisement

Each first communicates with the apps on your mobile device by broadcasting something called a UUID - a universally unique identifier.

That identifier allows the corresponding apps on your phone to recognise the Bluetooth device, creating a connection that allows your phone and device to talk to one another.

Advertisement

But that identifier itself is also embedded into the mobile app code. Otherwise, mobile apps would not be able to recognise the device. However, such UUIDs in the mobile apps make the devices vulnerable to a fingerprinting attack, the research team found.

"At a minimum, a hacker could determine whether you have a particular Bluetooth device, such as a smart speaker, at your home, by identifying whether or not your smart device is broadcasting the particular UUIDs identified from the corresponding mobile apps," Lin said.

Advertisement

"But in some cases in which no encryption is involved or encryption is used improperly between mobile apps and devices, the attacker would be able to 'listen in' on your conversation and collect that data."

Still, that doesn't mean you should throw your smartwatch away.

"We think the problem should be relatively easy to fix, and we've made recommendations to app developers and to Bluetooth industry groups," he said.

If app developers tightened defences in that initial authentication, the problem could be resolved, Lin said.

The team reported their findings to developers of vulnerable apps and to the Bluetooth Special Interest Group, and created an automated tool to evaluate all of the Bluetooth Low Energy apps in the Google Play Store - 18,166 at the time of their research.

In addition to building the databases directly from mobile apps of the Bluetooth devices in the market, the team's evaluation also identified 1,434 vulnerable apps that allow unauthorised access. Their analysis did not include apps in the Apple Store.

"It was alarming," he said. "The potential for privacy invasion is high."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Bluetooth
Advertisement

Related Stories

Popular Mobile Brands
  1. Redmi Pad 2 Pro 5G Will Launch in India Soon: See Expected Features
  2. Xiaomi 17 Ultra With Leica-Tuned Cameras Confirmed to Launch Soon
  3. Nvidia's GeForce RTX 50 Series GPUs Are About to Be Scarce
  4. GTA 6 Map Guide: Here's All You Need to Know About Different Areas
  5. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  6. Eko OTT Release Reportedly Revealed: When and Where to Watch it Online?
  7. You Can Now Vibe Code AI Mini Apps Within Gemini With This Tool
  8. Samsung Will Unveil These New Bespoke AI Devices at CES 2026
  9. Best ANC TWS Earbuds Under Rs 8,000: Sony WF-C710N, OnePlus Buds 4, More
  10. OnePlus Watch Lite With Up to 10 Days Battery Life Launched: See Price
  1. Adobe Firefly Platform Updated With New AI Models and Tools, Offers Limited-Time Unlimited Generations
  2. Boat Valour Ring 1 Launched in India With Heart Rate Variability Tracking, Up to 15-Day Battery Life: Price, Features
  3. Call of Duty: Black Ops 7 Was the Best-Selling Game in the US in November, but Trails Battlefield 6 in 2025
  4. Truecaller Voicemail Feature Launched for Android Users in India With Transcription in 12 Regional Languages
  5. OpenAI Starts Reviewing Third-Party App Submissions for ChatGPT Integration
  6. Google Brings Opal, an AI-Powered Mini App Builder Tool to Gemini
  7. Redmi Pad 2 Pro 5G India Launch Teased Soon After Global Debut: Expected Specifications, Features
  8. CES 2026: Samsung to Unveil Bespoke AI Laundry Combo, Jet Bot Steam Ultra Robot Vacuum, and More
  9. Samsung Exynos 2600 Details Leak Ahead of Galaxy S26 Launch; Could Be Equipped With 10-Core CPU, AMD GPU
  10. Vivo Y50e 5G, Vivo Y50s 5G Appear on Google Play Console; Mysterious Vivo Phone Listed on Certification Site
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.