New Bluetooth Bug With Remote Access Vulnerabilities Surfaces, Fix Deployed

Advertisement
By Ankit Chawla | Updated: 25 July 2018 13:08 IST
Highlights
  • The bug has affected both Bluetooth and Bluetooth LE's standards
  • Drivers from Apple, Broadcom, Intel, and Qualcomm have been affected
  • Software and firmware updates will roll out in the coming weeks

A new cryptographic bug has come to light that is claimed to affect the Bluetooth implementations of multiple operating system drivers manufactured by big corporations including Apple, Broadcom, Intel, Qualcomm, among others. A report suggests that this bug has occurred due to an insufficient validation of encryption parameters on secure Bluetooth connections. Tracked as CVE-2018-5383, this Bluetooth bug seems to have affected both the "Secure Simple Pairing" and "Secure Connections" processes of Bluetooth standard and Bluetooth LE, respectively.

As per a report by Bleeping Computer, Israeli scientists Lior Neumann and Eli Biham, from the Israel Institute of Technology, have discovered the CVE-2018-5383 bug. In a blog post on Monday, Bluetooth Special Interest Group (SIG) acknowledged the bug and stated that there is a possibility that some vendors may have developed Bluetooth-compatible products that do not perform public key validation during the pairing procedure. This can potentially give remote access to attackers who are within wireless range of two such vulnerable devices.

Advertisement

"The attacking device would need to intercept the public key exchange by blocking each transmission, sending an acknowledgement to the sending device, and then injecting the malicious packet to the receiving device within a narrow time window. If only one device had the vulnerability, the attack would not be successful," explained the blog post.

As a solution, the Bluetooth SIG has updated its Bluetooth specification to now require all public keys to be validated as part of the default security procedures, Adding to that, the SIG has also added testing for this vulnerability to its Bluetooth Qualification Program.

Advertisement

In a post by CERT, Microsoft is claimed to not have been affected by the Bluetooth bug. Additionally, this post also goes on to state the reason for this vulnerability.

"Bluetooth utilizes a device pairing mechanism based on elliptic-curve Diffie-Hellman (ECDH) key exchange to allow encrypted communication between devices. The ECDH key pair consists of a private and a public key, and the public keys are exchanged to produce a shared pairing key," it notes. "The devices must also agree on the elliptic curve parameters being used. Previous work on the "Invalid Curve Attack" showed that the ECDH parameters are not always validated before being used in computing the resulted shared key, which reduces attacker effort to obtain the private key of the device under attack if the implementation does not validate all of the parameters before computing the shared key."

Advertisement

According to Bleeping Computer, Apple, Broadcom, Intel, and Qualcomm have already issued software fixes for this vulnerability. Additionally, CERT was unable to detect whether devices running Google's software, AOSP, and Linux were affected or not. Software updates on laptops, desktops, and smartphones, and firmware updates on IoT devices are expected in the coming weeks.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Bluetooth, Apple, Intel, Broadcom, Qualcomm
Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Finally Rolls Out Its Health App Update With These Features
  2. This Upcoming OnePlus N6 Could Arrive With This MediaTek Chip in India
  3. Call of Duty: Black Ops, Black Ops 2 Ports Coming to PlayStation Next Month
  4. JBL Live 780NC, Live 680NC Debut in India With Up to 80-Hour Battery Life
  5. GTA 5 Owners to Get Free PS5, Xbox Series X/S Upgrades Ahead of New Heist
  6. Google Home Speaker Finally Makes Its Global Debut, Available to Pre-Order
  7. Poco C95 Pro 4G Bags Singapore's IMDA Certification, Might Arrive Soon
  8. The OnePlus 15R Is Now Available in a New 16GB RAM Variant at This Price
  9. Xiaomi 17T Review
  10. Amazon Prime Day Sale Dates Announced, Drops Prime Membership Price
  1. Vivo Y6e 5G Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  2. Tether to Cease Operations of Gold-Linked aUSDT Stablecoin
  3. Poco C95 Pro 4G Picks Up Singapore’s IMDA Certification; Could Arrive With Snapdragon 6s 4G Gen 2 Chip
  4. Xiaomi India CMO Anuj Sharma Steps Down After 8 Years
  5. iPhone Air 2 Said to Be in the Works, Could Launch in 2027 With Camera and Battery Upgrades
  6. Call of Duty: Black Ops and Black Ops 2 Are Being Ported to PlayStation Consoles Next Month
  7. Honor X80 Pro Max Key Specifications, Storage Options Revealed via China Telecom Listing Days Before Launch
  8. Vivo X Fold 6 Battery and Durability Details Teased Days Ahead of June 26 Launch
  9. GTA 5 Owners to Get Free PS5, Xbox Series X/S Version Upgrades Ahead of New Heist
  10. Amazon Prime Day 2026 Sale Dates Announced, Prime Membership Price Drops to Rs. 999
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.