Your Devices May Be Vulnerable to BIAS Bluetooth Attack: Report

BIAS Bluetooth attack can let an attacker connect to a target device without needing any authentication.

Advertisement
By Vineet Washington | Updated: 20 May 2020 18:59 IST
Highlights
  • BIAS attack exploits vulnerability in Bluetooth standard
  • All Bluetooth devices are vulnerable to this attack
  • Bluetooth SIG was made aware of this in December 2019

BIAS exploits Bluetooth Classic to gain access to another device

A Bluetooth flaw could leave your phone at risk and all devices appear to have this vulnerability. Researchers found a vulnerability they named Bluetooth Impersonation AttackS (BIAS) that can allow someone to gain access to a target device (such as a smartphone or laptop) by impersonating the identity of a previously paired device. The researchers found the vulnerability in December 2019, and informed the Bluetooth Special Interest Group (Bluetooth SIG) — the standards organisation that that oversees Bluetooth — about this. However, the issue has not been fully remedied as Bluetooth SIG has so far “encouraged” fixes from manufacturers, and recommended that users get the latest updates for their devices.

The research team said that the attack was tested against a wide range of devices, including smartphones from manufacturers like Apple, Samsung, Google, Nokia, LG, and Motorola, laptops from HP, Lenovo the Apple MacBook, headphones from Philips and Sennheiser, as well as iPads. They tried a BIAS attack on 31 Bluetooth devices with 28 unique Bluetooth chips from Apple, Qualcomm, Intel, Cypress, Broadcom, and others. All of the 31 attacks were successful. “Our attacks allow to impersonate Bluetooth master and slave devices and establish secure connections without knowing the long term key shared between the victim and the impersonated device,” the researchers stated. They added that this attack exploits lack of integrity protection, encryption, and mutual authentication in the Bluetooth standard.

Advertisement

What is BIAS?

Researchers Daniele Antonioli, Kasper Rasmussen, and Nils Ole Tippenhauer have noted that BIAS is a vulnerability found in the Bluetooth Basic Rate Extended Data Rate (BR/EDR) wireless technology, also called Bluetooth Classic. This technology is the standard for a wireless personal area network. A Bluetooth connection usually involves a connection between a host and a client device. When two devices are paired for the first time, a key or address is generated, which allows following Bluetooth connections between the two devices to be seamless. Even though the Bluetooth standard provides security features to protect against eavesdropping and/or manipulation of information, a BIAS attack can impersonate this key or address, and connect to a device without the need of authentication, since it would appear as if it had been previously paired.

Once connected, the attacker can gain access to a target device over a Bluetooth connection. This in turn can open up a number of possibilities for any kind of malicious attack on the device that has been targeted by BIAS. Additionally, the researchers noted that since the attack is standard compliant, it is effective against Legacy Secure Connections and Secure Connections, meaning all devices are vulnerable to this attack.

Advertisement

However, for this attack to be successful, an attacking device would need to be within wireless range of a vulnerable Bluetooth device that has previously established a BR/EDR bonding with a remote device with a Bluetooth address known to the attacker, Bluetooth SIG noted.

What can users do?

As per the Github page of the BIAS attack, this vulnerability was pointed out to Bluetooth Special Interest Group (Bluetooth SIG) – the organisation that oversees the development of Bluetooth standard, in December 2019. However, at the time of disclosure, the research team tested chips from Cypress, Qualcomm, Apple, Intel, Samsung, and CSR. It was found that all these devices were vulnerable to the BIAS attack. The researchers stated that some vendors might have implemented workarounds on their devices so if a user's device was not updated after December 2019, it may be vulnerable.

Advertisement

Bluetooth SIG also gave a statement in response to this vulnerability and said that it is working on a remedy. Bluetooth SIG is updating the Bluetooth Core Specification to clarify when role switches are permitted, to require mutual authentication in legacy authentication and to recommend checks for encryption-type to avoid a downgrade of secure connections to legacy encryption. These changes will be introduced into a future specification revision, it said.

It added, "The Bluetooth SIG is also broadly communicating details on this vulnerability and its remedies to our member companies and is encouraging them to rapidly integrate any necessary patches. As always, Bluetooth users should ensure they have installed the latest recommended updates from device and operating system manufacturers."


Which is the bestselling Vivo smartphone in India? Why has Vivo not been making premium phones? We interviewed Vivo's director of brand strategy Nipun Marya to find out, and to talk about the company's strategy in India going forward. We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts or RSS, download the episode, or just hit the play button below.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Nord 6 Series India Launch Teased as New Model Surfaces Online
  2. iQOO Z11x 5G With 7,200mAh Battery Goes on Sale in India: See Price, Offers
  3. Poco X8 Pro Series Camera, Display Features Revealed a Day Before Launch
  4. JBL Grip Portable Speaker With Up to 12 Hours Battery Life Launched in India
  5. OnePlus Nord 6 May Launch With Same Specifications as OnePlus Turbo 6
  6. Huawei Teases an Imminent Return to India With the Launch of This Tablet
  7. iPhone 19e Could Launch With This Major Display-Related Upgrade
  8. Realme C100 5G Retailer Listing Reveals Pricing and Features
  9. Claude Is Doubling the Usage Limits for the Next Two Weeks: Details
  10. Samsung Galaxy A37, Galaxy A57 Spied in Leaked Hands-on Videos
  1. Arc Raiders' AI Voice Lines Were Re-Recorded by Human Actors After Launch, Says Embark CEO
  2. Apple's iPhone 19e Said to Launch in 2028 With Upgraded LPTO OLED Display
  3. WLFI Governance Vote Passes Proposal Introducing Token Lock-Up Incentives
  4. Xiaomi Book Pro 14, Xiaomi Watch S5 China Launch Date Announced; Key Features Teased
  5. Realme C100 5G Listed on Retail Website With 6.8-Inch Display and 7,000mAh Battery
  6. Anthropic Doubles Claude’s Usage Limits for the Next Two Weeks: Details
  7. Australian Lawmakers Advance New Bill to Regulate Crypto Platforms
  8. Poco X8 Pro, Poco X8 Pro Max Camera Configuration and Display Features Revealed
  9. JBL Grip Portable Speaker With AI Sound Boost, Up to 12 Hours Battery Life Launched in India: Price, Features
  10. Samsung Begins Testing One UI 9 Beta for Galaxy S26 Ultra Ahead of Android 17 Release: Report
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.