Bluetooth is one of the most popular wireless communication standards on the market, but it has never been recognized as a robust asset when it comes to security. The latest crack in its armor manifests through BlueBorne, a new attack vector discovered by the security company Armis, which does not require links, strange connections, or manual connections. All it needs to work is for the user to leave Bluetooth enabled on a vulnerable device.

BlueBorne: The Dangerous Attack Vector Putting Bluetooth at Risk
BlueBorne

Security news is almost never good when it involves an established standard or protocol. In the past we have seen several examples of what can happen if a popular technology is compromised, but this time the risk takes on a completely different dimension. Bluetooth support is integrated into billions of devices that go beyond smartphones and/or tablets. Desktop computers, smart systems in cars, televisions and even refrigerators have Bluetooth connectivity. For that reason, the discovery of a new attack vector does not excite us much.

https://www.youtube.com/embed/LLNtZKpL0P8

The Scope of BlueBorne

The folks at Armis identified BlueBorne, a vector with the potential to reach almost 5.3 billion devices Bluetooth (out of a total of 8.2 billion) running different versions of Windows, Linux, iOS and Android. The most relevant detail of BlueBorne is that it does not require downloads, clicks on URL links, or connection to suspicious access points, but rather the user forgetting to turn off Bluetooth. The exploitation process takes less than ten seconds on average, and works even when the device under attack is connected to another. Armis also detected eight new 0-day vulnerabilities, four of which were classified as critical. A sufficiently skilled attacker could use BlueBorne to inject malware into a device and enable its rapid propagation to nearby units, within a maximum range of ten meters.

https://www.youtube.com/embed/Az-l90RCns8

Response and Recommendations

A positive detail we can take away from all this is the response from the major companies. Armis contacted Microsoft in April, and the corresponding update for Windows was published in July (a Microsoft spokesperson said that BlueBorne does not affect Windows Phone/Mobile). In the case of Apple, all iOS devices with versions 9.3.5 or earlier are vulnerable to BlueBorne, as is AppleTV 7.2.2 or lower. The situation is much more complex for Android and Linux users in general. Google has already published its patches, but the rest is in the hands of the OEMs, which always take their time. Armis has maintained open communication channels with the Linux kernel security team, and necessary hotfixes are on the way. In short, we must update our systems, or as an alternative in the absence of patches, minimize the use of Bluetooth.

Official site: