The new BIAS Bluetooth bug can break into Apple, Intel and Samsung devices | Tech News

The new BIAS Bluetooth bug can break into Apple, Intel and Samsung devices

  • The BIAS bug leverages the way in which devices handle link keys or long-term keys that get generated when two Bluetooth devices pair for the first time.

By: HT TECH
| Updated on: Aug 20 2022, 21:00 IST
As per researchers, the new BIAS attack works against any device that have Bluetooth and can attack devices across firmware from OEMs
As per researchers, the new BIAS attack works against any device that have Bluetooth and can attack devices across firmware from OEMs (Pixabay)

Bluetooth devices like smartphones, laptops and other IoT devices are vulnerable to a new BIAS Bluetooth attack, or Bluetooth Impersonation AttackS (BIAS), according to reports. As per researchers, the new BIAS attack works against any device that have Bluetooth and can attack devices and firmware from OEMs like Apple, Intel, Samsung, Broadcom, Cypress etc.

"We use our implementation to verify that the vulnerabilities in the authentication mechanisms are indeed present in real devices, and not just a quirk of the standard. We successfully attack 31 Bluetooth devices (28 unique Bluetooth chips) from major hardware and software vendors, representing all the major Bluetooth versions, including Apple, Qualcomm, Intel, Cypress, Broadcom, Samsung, and CSR," the researchers said in a statement.

You may be interested in

MobilesTablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage

Bluetooth tech is used for wireless communication across billions of devices and the Bluetooth standard includes a “legacy authentication procedure and a secure authentication procedure, thus allowing devices to authenticate each other with a long term key”. The BIAS bug leverages the way in which devices handle link keys or long-term keys that get generated when two Bluetooth devices pair for the first time.

Also read
Looking for a smartphone? To check mobile finder click here.

"Because this attack affects basically all devices that 'speak Bluetooth,' we performed a responsible disclosure with the Bluetooth Special Interest Group (Bluetooth SIG) - the standards organisation that oversees the development of Bluetooth standards - in December 2019 to ensure that workarounds could be put in place," the researchers noted.

The Bluetooth SIG has mentioned in a press note that the Bluetooth Core Specification has been updated “to prevent BIAS attackers from downgrading the Bluetooth Classic protocol from a secure authentication method to a legacy authentication mode where the BIAS attack is successful”.

"To remedy this vulnerability, the Bluetooth SIG is updating the Bluetooth Core Specification to clarify when role switches are permitted, to require mutual authentication in legacy authentication, and to recommend checks for encryption-type to avoid a downgrade of secure connections to legacy encryption. These changes will be introduced into a future specification revision," Bluetooth SIG said in a statement.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on Whatsapp channel,Twitter, Facebook, Google News, and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 21 May, 21:50 IST
Tags:
NEXT ARTICLE BEGINS