Bluetooth Vulnerability Exposes macOS, iOS, Linux, and Android Devices

The vulnerability only requires a basic Bluetooth adapter to exploit.

December 8, 2023

Bluetooth Logo on Keyboard
  • A Bluetooth authentication bypass vulnerability has been found to allow malicious actors to run arbitrary commands on Apple, Android, and Linux devices.
  • The flaw, CVE-2023-45866, is easy to exploit with a standard Bluetooth adapter to leverage unauthenticated pairing mechanisms.

A high-severity Bluetooth vulnerability has been found by a software engineer at drone tech firm SkySafe. The security flaw allows malicious actors to make unauthorized connections to Linux, Android, and Apple devices to run arbitrary commands. The flaw has been reported to Google, Apple, and Bluetooth SIG.

Known as CVE-2023-45866, the vulnerability bypasses the authentication system of Bluetooth systems. It connects to any discoverable host to easily inject keystrokes on the infiltrated device with the help of a standard Bluetooth adapter. Essentially, the flaw fools the targeted device into believing it is connected to a Bluetooth keyboard through an unauthenticated pairing mechanism.

Consequently, malicious actors in proximity to vulnerable devices can simply inject keystrokes, allowing for the installation of apps and the operation of arbitrary code. The attack does not require specialized hardware to work either.

See More: 7 Million Profiles Accessed in 23andMe Hack

The vulnerability potentially affects numerous devices that run on Android, iOS, Linux, and macOS. This flaw also works on Apple devices that are on LockDown Mode, a key Apple security feature.

According to Google, the vulnerability could result in privilege escalation threats, and fixes were available to OEMs for devices running Android versions 11 through 14. Pixel devices, in particular, are expected to be patched in December updates.

What best practices do you use to prevent digital threats? Let us know your thoughts on LinkedInOpens a new window , XOpens a new window , or FacebookOpens a new window . We’d love to hear from you!

Image source: Shutterstock

LATEST NEWS STORIES

Anuj Mudaliar
Anuj Mudaliar is a content development professional with a keen interest in emerging technologies, particularly advances in AI. As a tech editor for Spiceworks, Anuj covers many topics, including cloud, cybersecurity, emerging tech innovation, AI, and hardware. When not at work, he spends his time outdoors - trekking, camping, and stargazing. He is also interested in cooking and experiencing cuisine from around the world.
Take me to Community
Do you still have questions? Head over to the Spiceworks Community to find answers.