Billions of Wi-Fi and Bluetooth devices vulnerable to password and data theft attacks

Bluetooth
(Image credit: Shutterstock)

A new research paper has been published revealing that an attacker can extract passwords and manipulate web traffic on a Wi-Fi chip by targeting the Bluetooth component of mobile devices featuring multiple wireless technologies.

Smartphones, tablets and other modern mobile devices feature Systems on a Chip (SoC) that contain separate Bluetooth, Wi-Fi and LTE components each with their own dedicated security implication. However, these components often share many of the same resources like a device's antenna or wireless spectrum.

Researchers from the University of Darmstadt, Brescia, CNIT and the Secure Mobile Networking Lab have discovered that it's possible to use these shared resources as a bridge for launching lateral privilege escalation attacks across wireless chip boundaries according to a new report from Bleeping Computer.

If an attacker is able to exploit these vulnerabilities, they could achieve code execution, memory readout and denial of service.

Architecture and protocol flaws

In order to exploit these flaws, the researchers first needed to perform code execution on either the Bluetooth or Wi-Fi chip. After this was accomplished, they were then able to perform lateral attacks on a device's other chips by using shared memory resources.

In total, the researchers found nine different vulnerabilities and while some can be fixed with a firmware update, others can only be fixed by a new hardware revision which puts billions of existing devices at risk of potential attacks.

During their testing the researchers looked into chips from Broadcom, Silicon Labs and Cypress which are present in billions of devices. After they reported the flaws to these chip vendors, some have released security updates to address them. However, some haven't addressed them as they affect products that are no longer supported like the Nexus 5 and iPhone 6.

To prevent falling victim to any attacks exploiting these flaws, users should delete unnecessary Bluetooth device pairings, remove unused Wi-Fi networks from their device's settings and use mobile data instead of public Wi-Fi.

We'll likely hear more on these flaws once device manufacturers begin rolling out new firmware updates but unfortunately, some of these flaws may never be patched.

We've also featured the best endpoint protection software, best VPN and best wireless routers

Via Bleeping Computer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
Find My app logo displayed on an iPhone 11 screen
This Find My exploit lets hackers track any Bluetooth device – here’s how you can stay safe
MediaTek
MediaTek reveals host of security vulnerabilities, so patch now
A VPN runs on a mobile phone placed on a laptop keyboard
SonicWall firewalls hit by worrying cyberattack
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Apple users facing new security risks after critical USB component hacked
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Businessman holding a magnifier and searching for a hacker within a business team.
Cloud streaming hoster StreamElements confirms data breach following attack
Latest in News
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa Devices, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does
Nintendo Virtual Game Card
Nintendo reveals the new Virtual Game Card feature, an easier way to manage your digital Switch games
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA