There’s a new Bluetooth security vulnerability to be aware of, tracked as CVE-2018-5383, and it’s a nasty one.
It’s a cryptographic vulnerability that affects firmware or operating system software drivers from a number of major vendors, including Qualcomm, Broadcom, Intel and Apple. At this point, the implication of the bug on Linux, Android, and Google are unknown.
The flaw is related to two important Bluetooth features: BR/EDR implementations of Secure Simple Pairing in device firmware and Bluetooth Low Energy (BLE) of Secure Connections Pairing in OS system software.
It was discovered by researchers operating out of Israel’s Institute of Technology. They discovered that the Bluetooth specification recommends (but critically does not mandate) that devices supporting the two features make any effort to validate the public encryption key received during secure pairing.
Since the specification is optional, it’s hardly a surprise that some vendors producing Bluetooth products do not take sufficient steps to validate the parameters used to generate public keys during the exchange.
This allows a would-be hacker the possibility of executing a man-in-the-middle attack to obtain the cryptographic key used by the device. This would give them the opportunity to not only spy on the device’s owner, but also to inject malware that could allow the hacker to take full control over the device.
SIG (the Bluetooth Special Interest Group which maintains the technology), had this to say about the flaw:
“For an attack to be successful, an attacking device would need to be within wireless range of two vulnerable Bluetooth devices that were going through a pairing procedure.
The attacking device would need to intercept the public key exchange by blocking each transmission, sending an acknowledgement to the sending device, and then injecting the malicious packet to the receiving device within a narrow time window. If only one device had the vulnerability, the attack would not be successful.”
Bluetooth SIG has now updated the specification to require products to validate public keys received as part of the public key-based security procedures. Of the manufacturers mentioned above, Apple and Intel have both released patches. Broadcom has made fixes available to its OEM customers who are responsible for providing them to end-users. There has been no word yet from Qualcomm.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Positive Technologies has just released a new report that paints a grim picture for IT professionals. If your sense is that the number of cyberattacks are increasing, you’re not wrong. In fact, it’s probably worse than you realize.
On May 14th, the Billings Clinic in Montana issued a breach notification statement, which explained that they detected unusual activity within one of its employee’s email accounts.
As if there weren’t enough ways for hackers to steal your passwords, now, there’s thermal imaging. If that sounds like something straight out of a science fiction movie, think again.
Internet security researcher Vinny Trola recently made a huge and disturbing discovery. A marketing firm called Exactis had left a massive database unsecured, allowing anyone who stumbled across it to access it.
While a significant percentage of Americans are suspicious of government spending beyond the essentials, there’s at least one notable exception, according to a recent survey conducted by SecurityFirst.
Another week, another high-profile data breach. This time, Adidas and their online store was the target.
Researchers from Ruhr-Universität Bochum and New York University in Abu Dhabi have discovered serious security flaws in 4G LTE networks that allow hackers to spy on, listen in on, intercept, and disrupt phone calls and text messages.
Do you use Cortana? It’s a handy virtual assistant (like Siri) built into Windows 10. Unfortunately, as useful as she is, there’s a problem. Even if you don’t use Cortana yourself, take heed: Microsoft has recently issued a security update based on findings by McAfee researchers.
How many web apps do you have on your phone? Probably a ton. Here’s something you likely didn’t know. Based on the latest research from Positive Technologies, nearly half of them (48 percent) are vulnerable to unauthorized access.