Thursday, January 30, 2025
HomeAndroidNew Bluetooth Vulnerability in Android Let Remote Attackers Execute Arbitrary Code &...

New Bluetooth Vulnerability in Android Let Remote Attackers Execute Arbitrary Code & Silently Take Your Device Control

Published on

SIEM as a Service

Follow Us on Google News

A new critical Bluetooth vulnerability discovered in Android Bluetooth system that allows remote attackers silently execute arbitrary code remotely and take the complete device control.

Researchers discovered that the vulnerability affected Android Oreo 8.0 to Android Pie 9.0 and there is no user interaction required for attackers to exploit this vulnerability.

Due to technical reasons, Android 10 is not exploitable, but the vulnerability leads to crash the Bluetooth daemon.

Android versions even older than 8.0 might also be affected but the researchers did not evaluate the impact.

According to Insinuator report “In order to exploit the vulnerability, the attacker needs to be within the proximity range and the Bluetooth MAC address of the targeted device has to be known.”

Identifying the MAC is not a difficult part for the attackers, and the Bluetooth MAC address for some devices can be deduced from the WiFi MAC address.

Install the Latest Patch

The Vulnerability can be tracked as CVE-2020-0022, and the patch has been released in the latest security patch from February 2020.

Android released a security update that explains: “The most severe vulnerability could enable a remote attacker using a specially crafted transmission to execute arbitrary code within the context of a privileged process.”

This vulnerability can lead to theft of personal data and could potentially be used to spread malware and spy your android device remotely.

At the time of writing, there is no technical information available for this critical Bluetooth vulnerability. we will update you once we found the relevant technical details.

Mitigation

All the Android users are strongly advised to update the latest security patch released by Android.

Don’t enable your Bluetooth in your Android when you’re not using it.

Keep your device non-discoverable. Most are only discoverable if you enter the Bluetooth scanning menu. Nevertheless, some older phones might be discoverable permanently.

Also Read:

BLEEDINGBIT – Two Bluetooth Chip-level Vulnerabilities Affected Millions of Enterprise Wi-Fi Access Point Devices

Hackers Nearby can Hijack Bluetooth Titan Security Keys – Google Replacing it for Free

CarsBlues Bluetooth Hack Allows Hackers to Access Text Messages, Call Logs and More

Critical BlueBorne Vulnerability Puts More Than 5 Billion Bluetooth Enabled Devices Under Attack

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

New Apple SLAP & FLOP Side-Channel Attacks Let Attackers Steal Login Details From Browser

Researchers from the Georgia Institute of Technology and Ruhr University Bochum have uncovered two...

Hackers Exploit OAuth 2.0 Code Flow Using AiTM Attack on Microsoft Azure AD

Security enthusiasts and professionals are turning their focus towards a new angle on phishing...

Russian APT28 Hackers Exploit Zero-Day Vulnerabilities to Target Government and Security Sectors

A detailed analysis from Maverits, a leading cybersecurity firm, reveals a significant evolution in...

Lynx Ransomware Architecture to Attack Windows, Linux, ESXi Uncovered

The emergence of the Lynx Ransomware-as-a-Service (RaaS) platform has drawn significant attention in cybersecurity...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Windows CLFS Buffer Overflow Vulnerability CVE-2024-49138 – PoC Released

 A recently disclosed Windows kernel-level vulnerability, identified as CVE-2024-49138, has raised significant security concerns in...

Zyxel CPE Zero-Day (CVE-2024-40891) Exploited in the Wild

Security researchers have raised alarms about active exploitation attempts targeting a newly discovered zero-day...

Windows 11 24H2 Update Bug: Users Report Disruptions in Web Camera and USB Devices

Windows 11 KB5050009 for version 24H2 has sparked widespread frustrations among users due to...