A years-old Bluetooth authentication bypass vulnerability allows miscreants to connect to Apple, Android and Linux devices and inject keystrokes to run arbitrary commands, according to a software engineer at drone technology firm SkySafe. The bug, tracked as CVE-2023-45866, doesn't require any special hardware to exploit, and the attack can be pulled off from a Linux machine using a regular Bluetooth adapter, says Marc Newlin, who found the flaw and reported it to Apple, Google, Canonical, and Bluetooth SIG. Newlin says he'll provide vulnerability details and proof-of-concept code at an upcoming conference but wants to hold off until everything is patched. The attack allows a nearby intruder to inject keystrokes and execute malicious actions on victims' devices, as long as they don't require a password or biometric authentication. In a GitHub post published on Wednesday, the bug hunter describes the security flaw thus: "The vulnerabilities work by tricking the Bluetooth host state-machine into pairing with a fake keyboard without user-confirmation. The underlying unauthenticated pairing mechanism is defined in the Bluetooth specification, and implementation-specific bugs expose it to the attacker." Regulars readers may remember Newlin from a similar set of Bluetooth flaws he uncovered in 2016. These, dubbed MouseJack, exploited keystroke-injection vulnerabilities in wireless mice and keyboards from 17 different vendors. CVE-2023-45866, however, is even older than MouseJack. N...
Apple and some Linux distros are open to Bluetooth attack
The Register
·Jessica Lyons Hardcastle
·Published Dec 6, 2023
·Updated
Affected Software
8 affected components
Apple iOS and iPadOS
macOS
Android Android=4.2.2-10
Linux Linux
Ubuntu Ubuntu=18.04
Ubuntu Ubuntu=20.04
Ubuntu Ubuntu=22.04
Ubuntu Ubuntu=23.10
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a Bluetooth vulnerability that affects Apple and certain Linux devices, allowing attackers to bypass authentication and inject keystrokes.
2
What security implications are discussed?
The vulnerability could enable unauthorized access to devices, allowing attackers to execute arbitrary commands remotely.
3
What products or software are affected by the Bluetooth vulnerability?
Affected products include Apple iOS, iPadOS, macOS, Android (version 4.2.2-10), and specific versions of Ubuntu (18.04, 20.04, 22.04, and 23.10).
4
Who reported the vulnerability and when?
The vulnerability was reported by a software engineer from SkySafe, a drone technology firm.
5
What actions can users take to mitigate this vulnerability?
Users should update their devices and software to the latest versions and disable Bluetooth connections when not in use.