Tuesday, February 11, 2025
HomeAndroidNew Bluetooth Vulnerability in Android Let Remote Attackers Execute Arbitrary Code &...

New Bluetooth Vulnerability in Android Let Remote Attackers Execute Arbitrary Code & Silently Take Your Device Control

Published on

SIEM as a Service

Follow Us on Google News

A new critical Bluetooth vulnerability discovered in Android Bluetooth system that allows remote attackers silently execute arbitrary code remotely and take the complete device control.

Researchers discovered that the vulnerability affected Android Oreo 8.0 to Android Pie 9.0 and there is no user interaction required for attackers to exploit this vulnerability.

Due to technical reasons, Android 10 is not exploitable, but the vulnerability leads to crash the Bluetooth daemon.

Android versions even older than 8.0 might also be affected but the researchers did not evaluate the impact.

According to Insinuator report “In order to exploit the vulnerability, the attacker needs to be within the proximity range and the Bluetooth MAC address of the targeted device has to be known.”

Identifying the MAC is not a difficult part for the attackers, and the Bluetooth MAC address for some devices can be deduced from the WiFi MAC address.

Install the Latest Patch

The Vulnerability can be tracked as CVE-2020-0022, and the patch has been released in the latest security patch from February 2020.

Android released a security update that explains: “The most severe vulnerability could enable a remote attacker using a specially crafted transmission to execute arbitrary code within the context of a privileged process.”

This vulnerability can lead to theft of personal data and could potentially be used to spread malware and spy your android device remotely.

At the time of writing, there is no technical information available for this critical Bluetooth vulnerability. we will update you once we found the relevant technical details.

Mitigation

All the Android users are strongly advised to update the latest security patch released by Android.

Don’t enable your Bluetooth in your Android when you’re not using it.

Keep your device non-discoverable. Most are only discoverable if you enter the Bluetooth scanning menu. Nevertheless, some older phones might be discoverable permanently.

Also Read:

BLEEDINGBIT – Two Bluetooth Chip-level Vulnerabilities Affected Millions of Enterprise Wi-Fi Access Point Devices

Hackers Nearby can Hijack Bluetooth Titan Security Keys – Google Replacing it for Free

CarsBlues Bluetooth Hack Allows Hackers to Access Text Messages, Call Logs and More

Critical BlueBorne Vulnerability Puts More Than 5 Billion Bluetooth Enabled Devices Under Attack

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

SHA256 Hash Calculation from Data Chunks

The SHA256 algorithm, a cryptographic hash function, is widely used for securing data integrity...

New Report of of 1M+ Malware Samples Show Application Layer Abused for Stealthy C2

A recent analysis of over one million malware samples by Picus Security has revealed...

Seven-Year-Old Linux Kernel Bug Opens Door to Remote Code Execution

Researchers have uncovered a critical vulnerability in the Linux kernel, dating back seven years,...

Ransomware Payments Plunge 35% as More Victims Refuse to Pay

In a significant shift within the ransomware landscape, global ransom payments plummeted by 35%...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Marvel Game Vulnerability Exposes PCs & PS5s to Remote Takeover Attacks

A severe security vulnerability has been uncovered in the popular video game Marvel Rivals, raising...

Critical Zimbra Flaws Allow Attackers to Gain Unauthorized Access to Sensitive Data

Serious vulnerabilities in Zimbra Collaboration Suite (ZCS), a popular enterprise email and collaboration platform,...

Hackers Exploit AnyDesk Vulnerability to Gain Admin Access – PoC Released

A newly discovered vulnerability in AnyDesk, the popular remote desktop software, has sparked serious...