HT TECH wants to start sending you push notifications. Click allow to subscribe

The new BIAS Bluetooth bug can break into Apple, Intel and Samsung devices

  • The BIAS bug leverages the way in which devices handle link keys or long-term keys that get generated when two Bluetooth devices pair for the first time.

By: HT TECH
Updated on: Aug 20 2022, 21:00 IST
As per researchers, the new BIAS attack works against any device that have Bluetooth and can attack devices across firmware from OEMs (Pixabay)
As per researchers, the new BIAS attack works against any device that have Bluetooth and can attack devices across firmware from OEMs (Pixabay)

Bluetooth devices like smartphones, laptops and other IoT devices are vulnerable to a new BIAS Bluetooth attack, or Bluetooth Impersonation AttackS (BIAS), according to reports. As per researchers, the new BIAS attack works against any device that have Bluetooth and can attack devices and firmware from OEMs like Apple, Intel, Samsung, Broadcom, Cypress etc.

"We use our implementation to verify that the vulnerabilities in the authentication mechanisms are indeed present in real devices, and not just a quirk of the standard. We successfully attack 31 Bluetooth devices (28 unique Bluetooth chips) from major hardware and software vendors, representing all the major Bluetooth versions, including Apple, Qualcomm, Intel, Cypress, Broadcom, Samsung, and CSR," the researchers said in a statement.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹115,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,999₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹30,990₹51,990
Buy now
35% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,678₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

Bluetooth tech is used for wireless communication across billions of devices and the Bluetooth standard includes a “legacy authentication procedure and a secure authentication procedure, thus allowing devices to authenticate each other with a long term key”. The BIAS bug leverages the way in which devices handle link keys or long-term keys that get generated when two Bluetooth devices pair for the first time.

Also read: Looking for a smartphone? To check mobile finder click here.

"Because this attack affects basically all devices that 'speak Bluetooth,' we performed a responsible disclosure with the Bluetooth Special Interest Group (Bluetooth SIG) - the standards organisation that oversees the development of Bluetooth standards - in December 2019 to ensure that workarounds could be put in place," the researchers noted.

The Bluetooth SIG has mentioned in a press note that the Bluetooth Core Specification has been updated “to prevent BIAS attackers from downgrading the Bluetooth Classic protocol from a secure authentication method to a legacy authentication mode where the BIAS attack is successful”.

"To remedy this vulnerability, the Bluetooth SIG is updating the Bluetooth Core Specification to clarify when role switches are permitted, to require mutual authentication in legacy authentication, and to recommend checks for encryption-type to avoid a downgrade of secure connections to legacy encryption. These changes will be introduced into a future specification revision," Bluetooth SIG said in a statement.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 21 May, 21:50 IST
Tags:

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
8% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹82,600₹89,900
Buy now
35% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999₹39,999
Buy now
53% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹21,999₹47,000
Buy now
36% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹18,449₹28,999
Buy now
31% OFF
Samsung Galaxy Tab A7 Lite
  • Silver
  • 3 GB RAM
  • 32 GB Storage
₹9,990₹14,500
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
24% OFF
Asus ROG Strix G15 G512LI HN057T Laptop
  • Black
  • 16 GB RAM
  • 512 GB SSD
₹68,990₹90,990
Buy now
42% OFF
MSI Modern 15 A5M 055IN Laptop
  • Black
  • 8 GB RAM
  • 512 GB SSD
₹35,990₹61,990
Buy now
29% OFF
Asus VivoBook 15X OLED K3504VA LK541WS Laptop
  • Indie Black
  • 16 GB RAM
  • 512 GB SSD
₹65,980₹92,990
Buy now
NEXT ARTICLE BEGINS