Update 3/9/25: After receiving concerns about the use of the term 'backdoor' to refer to these undocumented commands, we have updated our title and story. Our original story can be found here. The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains undocumented commands that could be leveraged for attacks. The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence. This was discovered by Spanish researchers Miguel Tarascó Acuña and Antonio Vázquez Blanco of Tarlogic Security, who presented their findings yesterday at RootedCON in Madrid. "Tarlogic Security has detected a backdoor in the ESP32, a microcontroller that enables WiFi and Bluetooth connection and is present in millions of mass-market IoT devices," reads a Tarlogic announcement shared with BleepingComputer. "Exploitation of this backdoor would allow hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls." The researchers warned that ESP32 is one of the world's most widely used chips for Wi-Fi + Bluetooth connectivity in IoT (Internet of Things) devices, so the risk is significant. In their RootedCON presentation, the Tarlogic researchers explained that interest in Bluetooth security research has wan...
Undocumented commands found in Bluetooth chip used by a billion devices
BleepingComputer
·Bill Toulas
·Published Mar 8, 2025
·Updated
Affected Software
2 affected components
Espressif ESP32 microchip
Espressif ESP32
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery of undocumented commands in the widely used ESP32 Bluetooth chip.
2
What security implications are discussed regarding the undocumented commands?
The presence of undocumented commands raises concerns about potential security vulnerabilities in devices using the ESP32 chip.
3
How many devices are potentially affected by this Bluetooth chip vulnerability?
The ESP32 microchip is used in approximately one billion devices, indicating a widespread potential impact.
4
Who is the manufacturer of the affected Bluetooth chip?
The affected Bluetooth chip is manufactured by Espressif.
5
Has the term 'backdoor' been used in relation to the undocumented commands?
Initially, the term 'backdoor' was used to describe the undocumented commands, but it was later updated in the article to avoid confusion.