Tuesday, May 6, 2025
HomeAndroidNew Bluetooth Vulnerability in Android Let Remote Attackers Execute Arbitrary Code &...

New Bluetooth Vulnerability in Android Let Remote Attackers Execute Arbitrary Code & Silently Take Your Device Control

Published on

SIEM as a Service

Follow Us on Google News

A new critical Bluetooth vulnerability discovered in Android Bluetooth system that allows remote attackers silently execute arbitrary code remotely and take the complete device control.

Researchers discovered that the vulnerability affected Android Oreo 8.0 to Android Pie 9.0 and there is no user interaction required for attackers to exploit this vulnerability.

Due to technical reasons, Android 10 is not exploitable, but the vulnerability leads to crash the Bluetooth daemon.

- Advertisement - Google News

Android versions even older than 8.0 might also be affected but the researchers did not evaluate the impact.

According to Insinuator report “In order to exploit the vulnerability, the attacker needs to be within the proximity range and the Bluetooth MAC address of the targeted device has to be known.”

Identifying the MAC is not a difficult part for the attackers, and the Bluetooth MAC address for some devices can be deduced from the WiFi MAC address.

Install the Latest Patch

The Vulnerability can be tracked as CVE-2020-0022, and the patch has been released in the latest security patch from February 2020.

Android released a security update that explains: “The most severe vulnerability could enable a remote attacker using a specially crafted transmission to execute arbitrary code within the context of a privileged process.”

This vulnerability can lead to theft of personal data and could potentially be used to spread malware and spy your android device remotely.

At the time of writing, there is no technical information available for this critical Bluetooth vulnerability. we will update you once we found the relevant technical details.

Mitigation

All the Android users are strongly advised to update the latest security patch released by Android.

Don’t enable your Bluetooth in your Android when you’re not using it.

Keep your device non-discoverable. Most are only discoverable if you enter the Bluetooth scanning menu. Nevertheless, some older phones might be discoverable permanently.

Also Read:

BLEEDINGBIT – Two Bluetooth Chip-level Vulnerabilities Affected Millions of Enterprise Wi-Fi Access Point Devices

Hackers Nearby can Hijack Bluetooth Titan Security Keys – Google Replacing it for Free

CarsBlues Bluetooth Hack Allows Hackers to Access Text Messages, Call Logs and More

Critical BlueBorne Vulnerability Puts More Than 5 Billion Bluetooth Enabled Devices Under Attack

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

BFDOOR Malware Targets Organizations to Establish Long-Term Persistence

The BPFDoor malware has emerged as a significant threat targeting domestic and international organizations,...

Uncovering the Security Risks of Data Exposure in AI-Powered Tools like Snowflake’s CORTEX

As artificial intelligence continues to reshape the technological landscape, tools like Snowflake’s CORTEX Search...

UNC3944 Hackers Shift from SIM Swapping to Ransomware and Data Extortion

UNC3944, a financially-motivated threat actor also linked to the group known as Scattered Spider,...

Over 2,800 Hacked Websites Targeting MacOS Users with AMOS Stealer Malware

Cybersecurity researcher has uncovered a massive malware campaign targeting MacOS users through approximately 2,800...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Android Security Update -A Critical RCE Vulnerability Actively Exploited in the Wild 

Google has released critical security patches for Android devices to address 57 vulnerabilities across...

Samsung MagicINFO 9 Server Vulnerability Actively Exploited in the Wild

A critical security vulnerability in the Samsung MagicINFO 9 Server has come under active...

CISA Issues Alert on Langflow Vulnerability Actively Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert regarding an actively...