Skip to main content

Expert says risk of Bluetooth ‘BlueBorne’ attacks across multiple devices overblown

Security firm says 'BlueBorne' is only a risk if your device isn't updated

Armis - BlueBorne Explained
Bluetooth was originally created in 1998 to serve as a secure short-range wireless connection between two devices. It pairs our wireless mice to our laptops, our smartwatches to our smartphones, and so on. But a recent report published by security firm Armis points to eight Bluetooth-related vulnerabilities — four of which are critical — that reside on more than 5 billion Android, Windows, Linux, and pre-iOS 10 devices. The company dubs this “epidemic” BlueBorne.

“These vulnerabilities are the most serious Bluetooth vulnerabilities identified to date,” Armis said on September 12. “Previously identified flaws found in Bluetooth were primarily at the protocol level. These new vulnerabilities are at the implementation level, bypassing the various authentication mechanisms, and enabling a complete takeover of the target device.”

The problem starts with the complexity of Bluetooth itself. The specification stretches across 2,822 pages, which is massive compared to the base Wi-Fi specification (802.11), which consists of only 450 pages. Because of its complexity, Bluetooth does not receive the same scrutinized audits as other less-complicated protocols. That means vulnerabilities get buried as Bluetooth evolves.

Many issues prior to Bluetooth v2.1 were resolved with the introduction of Secure Simple Pairing, thus the security community shifted its attention away from Bluetooth. But a thorough inspection still needed to be performed and Armis says that its discovery of eight vulnerabilities in a recent analysis of Bluetooth could very well be “the tip of the iceberg.”

Overall, the BlueBorne set of vulnerabilities can enable a hacker to take control of a device, access its content, and use it to infect other Bluetooth-enabled devices with malware. Outside the actual vulnerabilities, the root of the issue stems from keeping Bluetooth turned on. A device will listen for Bluetooth traffic even if it is not set to discoverable mode, so all a hacker needs to know is its Bluetooth device address (BDADDR), and its MAC address.

But how do you get this information? By using open-source hardware sold online that can sniff out encrypted Bluetooth connections passing through the air. These packets of information contain plain text data pointing to the Bluetooth device address. Hackers can then use that address to send unicast traffic if they are within physical proximity of the target device: 33 feet for mobile phones and headsets, and 328 feet for laptops and desktops.

“If the device generates no Bluetooth traffic, and is only listening, it is still possible to ‘guess’ the BDADDR, by sniffing its Wi-Fi traffic,” the firm explains. “This is viable since Wi-Fi MAC addresses appear unencrypted over the air, and due to the MACs of internal Bluetooth/Wi-Fi adapters are either the same, or only differ in the last digit.”

But according to Mike Weber of cyber risk management service provider Coalfire, there is no need to panic. There are no known instances of hackers taking advantage of the vulnerabilities. Even more, creating malware to possibly attack a multitude of devices spanning Windows, iOS, and Linux in a single sweep would be extremely difficult. The discovery of the vulnerabilities only points to possibilities, not an actual attack in the wild.

“If you are on a device that is no longer supported, cannot be updated, or has not yet received a patch from a vendor, it is recommended to keep Bluetooth on the device turned off except when necessary,” Weber suggests.

Microsoft produced a patch for Windows on September 12, 2017. Apple nuked the vulnerabilities on its products with the release of iOS 10, but all devices running iOS 9.3.5 and older are still vulnerable. Google patched the issues on Android 6.0 (Marshmallow) and Android 7.0 (Nougat) on August 7, 2017, but if you’re still worried about BlueBorne, Armis Security provides an app on the Google Play Store.

Updated: Now reflects new information provided by Coalfire.

Kevin Parrish
Former Digital Trends Contributor
Kevin started taking PCs apart in the 90s when Quake was on the way and his PC lacked the required components. Since then…
The best web browsers for 2024
Lenovo IdeaPad 530S

All web browsers have the same basic function, and yet, the choice between them has always been one of the most contentious in tech history. You have more options these days than ever before, whether you're looking for the best web browser for privacy, the best for speed, or perhaps something a bit more adventurous.

To help you decide on the best web browser, we grabbed the latest browsers and put them through their paces. Even if some could use a complete overhaul, these options are your best chance for a great online experience.
The best web browser: Google Chrome
Google Chrome version 116 Mark Coppock / Digital Trends
Chrome is ubiquitous -- and for good reason. With a robust feature set, full Google Account integration, a thriving extension ecosystem (available through the Chrome Web Store), and a reliable suite of mobile apps, it’s easy to see why Chrome is the most popular and the best web browser.
Chrome boasts some of the most extensive mobile integration available. Served up on every major platform, keeping data in sync is easy, making browsing between multiple devices a breeze. Sign in to your Google account on one device, and all Chrome bookmarks, saved data, and preferences come right along. Even active extensions stay synchronized across devices.
Chrome's Password Manager can automatically generate and recommend strong passwords when a user creates a new account on a webpage. Managing saved passwords and adding notes to passwords is even easier. The search bar, or Omnibox, provides "rich results" comprised of useful answers, and it now supports generative AI capabilities. Favorites are more accessible as well, and they're manageable on the New Tab page. And it's now easier to mute tabs to avoid unwanted sounds.

Read more
Squarespace free trial: Build and host your website for free
Squarespace Fluid Engine screenshot.

With so many folks running their own websites these days, you may be considering getting one for yourself, and it's actually surprisingly easy to build a website without a ton of effort. Even better, Squarespace is one of the biggest and most well-known website builders out there, and even offers things like domain hosting and Squarespace courses, which is pretty interesting. Of course, it is quite a financial investment, even if you take advantage of one of these Squarespace deals, so you'll be happy to know that there's a great free trial to test out if Squarespace is the service for you.
Is there a Squarespace free trial?

Yup, there's a Squarespace free trial. You don't even need a credit card to start out with one of the best website builders -- Squarespace -- so there's absolutely no risk. All you need to do is pick out a template that works for your needs and go from there.

Read more
The next big Windows 11 update has a new hardware requirement
Windows 11 device sitting on a stool.

Microsoft’s upcoming Windows 11 24H2 update is expected to arrive with yet another hardware requirement. Centered around SSE4.2 or Streaming SIMD Extensions 4.2, a crucial component for modern processors, the new Windows 11 24H2 with build 26080 will only boot on CPUs that support the instruction set.

This information comes from Bob Pony on X (previously known as Twitter), following earlier reports in February where he claimed that CPUs lacking support for the POPCNT instruction were no longer compatible with Windows 11. The updated requirement is essentially the same, except that they now mandate the entire SSE 4.2 instruction set instead of just the POPCNT instruction within it, as was previously required.

Read more