'ATFuzzer' Android Baseband Security Threat Exploits Malicious Bluetooth, USB Accessories: Researchers

Bluetooth headsets and speakers, and even USB chargers, might be modified to attack your phone

Advertisement
By Jamshed Avari | Updated: 11 November 2019 18:41 IST
Highlights
  • The team of researchers will present a paper at an upcoming conference
  • The phones tested were older, but others might also be vulnerable
  • Manufacturers were given 90 days before the flaw was publicised

A new security exploit affecting several high-profile Android smartphones through maliciously modified Bluetooth and USB accessories has been discovered. Researchers at Purdue University and the University of Iowa have published a paper detailing how the baseband processors of several popular Android smartphones can be compromised in order to grant a an attacker wide-ranging permissions. By using specially crafted Bluetooth or USB accessories, the researchers were able to demonstrate how such modified accessories or even man-in-the-middle techniques can be used to execute instructions known as AT commands to control the baseband's functionality. The study examined multiple devices from Samsung, LG, HTC, Google, Motorola, and Huawei which are older models but still widely in use.

Amongst other things, the researchers were able to intercept IMEI numbers and network and roaming status, which can potentially be used to identify or track targets. They were also able to perform Denial of Service (DoS) attacks, disrupt Internet connectivity, and trigger functions such as DND, call forwarding, call blocking, and much more. Standard AT commands from publicly available 3GPP documentation. 

Ten devices from six manufacturers were tested; the Samsung Galaxy S8+ (Review), Google Pixel 2 (Review), Huawei Nexus 6P (Review), and Motorola Nexus 6 (Review), as well as the older Samsung Galaxy Note 2, Samsung Galaxy S3, LG G3, LG Nexus 5, HTC Desire 10 Lifestyle, and Huawei P8 Lite. Not all were found to be vulnerable to both USB and Bluetooth attack vectors. Accessories such as headsets, speakers, and even chargers could potentially be used to attack phones in this manner.

Advertisement

According to the research team, smartphones are not supposed to expose the AT command interface to Bluetooth and USB inputs in such a manner. The research paper is available to read, and details of the exploit itself can be found in a Github repository, as pointed out by Techcrunch. The paper will be presented at the 35th Annual Computer Security Applications Conference in December.

Advertisement

The affected phones used baseband processors manufactured by Qualcomm, Samsung, and HiSilicon (a subsidiary of Huawei). The researchers notified all the affected smartphone and baseband vendors, and waited the customary 90 days before going public with their findings. Samsung has committed to releasing patches for its devices. 

As always, users are cautioned that there are risks in connecting to unknown accessories or even using public chargers.  

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Bluetooth, Android, Security
Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Great Indian Festival 2025 Sale Will Begin on This Date
  2. Top OTT Releases of the Week (Sept 1 - Sept 7): Know What to Watch
  3. Flipkart Big Billion Days Sale Date Revealed, Will Compete With Amazon Sale
  4. Amazon Great Indian Festival 2025: Smartphone Deals Teased Ahead of Sale
  5. Samsung Galaxy S25 FE Launched With Exynos 2400 SoC: See Price
  6. Lava Bold N1 5G Launches in India Under Rs. 7,500 With These Features
  7. Oppo Reno 14 FS 5G Launches in Select Global Markets With These Features
  8. Motorola G06 to Debut With MediaTek Helio SoC, IP64 Rating: Report
  9. Samsung Galaxy S24 5G With Snapdragon 8 Gen 3 Chip to Launch in India Soon
  10. Samsung Launches Galaxy Tab S11 Series With Galaxy AI, These Features
  1. Moto Book 60 Pro Launched in India With Up to Intel Core Ultra 7 CPU, 14-Inch OLED Screen
  2. OpenAI to Challenge LinkedIn With New AI-Powered Jobs Platform in 2026
  3. Samsung Galaxy S24 5G With Snapdragon 8 Gen 3 Chip Confirmed to Launch in India, Will Go on Sale via Flipkart
  4. Huawei FreeBuds 7i Launched With ANC, Spatial Audio Support: Price, Specifications
  5. Bitcoin Holds Steady As Ethereum Gains From Strong ETF Demand
  6. Lava Bold N1 5G Launched in India With 90Hz HD+ Display and 13-Megapixel Rear Camera: Price, Specifications
  7. Hollow Knight: Silksong's Massive Launch Crashes Steam, PlayStation, Xbox and Nintendo Storefronts
  8. Amazon Great Indian Festival 2025: Deals on Samsung Galaxy S24 Ultra, iPhone 15, OnePlus 13s Teased Ahead of Sale
  9. Adobe Premiere App for iOS Introduced With Desktop-Like Controls, Generative AI Tools
  10. Motorola G06 to Reportedly Debut With MediaTek Helio G81 Extreme SoC; Check Expected Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.