The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains an undocumented backdoor that could be leveraged for attacks. The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence. This was discovered by Spanish researchers Miguel Tarascó Acuña and Antonio Vázquez Blanco of Tarlogic Security, who presented their findings yesterday at RootedCON in Madrid. The researchers warned that ESP32 is one of the world's most widely used chips for Wi-Fi + Bluetooth connectivity in IoT (Internet of Things) devices, so the risk of any backdoor in them is significant. In their RootedCON presentation, the Tarlogic researchers explained that interest in Bluetooth security research has waned but not because the protocol or its implementation has become more secure. Instead, most attacks presented last year didn't have working tools, didn't work with generic hardware, and used outdated/unmaintained tools largely incompatible with modern systems. Tarlogic developed a new C-based USB Bluetooth driver that is hardware-independent and cross-platform, allowing direct access to the hardware without relying on OS-specific APIs. Armed with this new tool, which enables raw access to Bluetooth traffic, Targolic discovered hidden vendor-specific commands (Opcode 0x3F) in the ESP32 Bluetooth firmware that allow low-level co...
Undocumented backdoor found in Bluetooth chip used by a billion devices
BleepingComputer
·Bill Toulas
·Published Mar 8, 2025
·Updated
Affected Software
2 affected components
Espressif ESP32
Espressif ESP32
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses an undocumented backdoor found in the ESP32 Bluetooth chip manufactured by Espressif.
2
What security implications are discussed?
The backdoor could potentially be exploited by attackers to spoof devices or gain unauthorized access.
3
What products or software are affected?
The affected product is the ESP32 microchip used in a billion devices.
4
Who is the manufacturer of the affected chip?
The manufacturer of the ESP32 chip is a Chinese company called Espressif.
5
How widespread is the use of the ESP32 chip?
The ESP32 microchip is used in over one billion units as of 2023.