Monday, April 14, 2025
HomeBluetoothSweynTooth - 11 Bluetooth Bugs That Affected SoC Vendors Let Hackers to...

SweynTooth – 11 Bluetooth Bugs That Affected SoC Vendors Let Hackers to Crash The Device & Execute the Code Remotely

Published on

SIEM as a Service

Follow Us on Google News

A group of security researchers uncovered a 12 Bluetooth based vulnerabilities dubbed “SweynTooth” in BLE software development kits of seven major system-on-a-chip (SoC) vendors.

 BLE ( Bluetooth Low Energy) a technology developed for wireless communication with a set of many standardized protocols that provide remote connectivity and also specifically handles the battery life of the device different power consumption and usage capabilities.

We have recently reported another critical Bluetooth vulnerability discovered in the Android Bluetooth system that allows remote attackers to silently execute arbitrary code remotely and take the complete device control.

- Advertisement - Google News

Now researchers from Singapore University of Technology and Design reported the new set of vulnerabilities in BLE SoC implementations allow attackers to perform deadlocks, crashes and buffer overflow or completely bypass security within the radio range and the different circumstances.

Also, SweynTooth vulnerabilities affected various IoT products in appliances such as smart-homes, wearables and environmental tracking or sensing, medical and logistics products.

SweynTooth
Some of the vulnerable IoT products

Vulnerable BLE SDKs sold by seven vendors of the following:

  • Texas Instruments
  • NXP
  • Cypress
  • Dialog Semiconductors
  • Microchip
  • STMicroelectronics
  • Telink Semiconductor

Type of Vulnerabilities

There are 3 types of major SweynTooth flaw identified in this research and each vulnerability impact the devices in different ways,

Crash :

Six Bluetooth vulnerabilities are addressed that lead to crash a device once the attacker triggers the vulnerabilities due to some incorrect code behavior or memory corruption.

According to the finding report, “when a buffer overflow on BLE reception buffer occurs. When a device crash occurs, they usually restart. However, such a restart capability depends on whether a correct hard fault handling mechanism was implemented in the product that uses the vulnerable BLE SoC.”

This vulnerability affected the vendors including Cypress, NXP, Dialog Semiconductors, Texas Instruments, Microchip, Telink Semiconductor.

Deadlock:

There are 3 vulnerabilities related to Deadlock type that affect the availability of the BLE connection without causing a hard fault or memory corruption.

Researchers explain that they usually occurred due to some improper synchronization between user code and the SDK firmware distributed by the SoC vendor, leaving the user code being stuck at some point.

There are 3 Vendors affected by these vulnerabilities: Cypress, NXP, STMicroelectronics.

3. Security Bypass:

Security bypass type Bluetooth vulnerability in SweynTooth consider as a “Critical” one and the vulnerability allows attackers in radio range to bypass the latest secure pairing mode of BLE.

Successfully exploit this vulnerability allow attack to perform an arbitrary read or write access to the device’s functions remotely.

Attackers also perform smart luggage lock that can be remotely locked or unlocked through a smartphone app.

This Zero LTK Installation security bypass Bluetooth vulnerability ( CVE-2019-19194 ) affected only Zero LTK Installation.

You can also read the detailed and in-depth technical details here.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

BPFDoor Malware Uses Reverse Shell to Expand Control Over Compromised Networks

A new wave of cyber espionage attacks has brought BPFDoor malware into the spotlight...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...

Morocco Investigation Major Data Breach Allegedly Claimed by Algerian Hackers

The National Social Security Fund (CNSS) of Morocco has confirmed that initial checks on...

Smishing Campaign Hits Toll Road Users with $5 Payment Scam

Cybersecurity researchers at Cisco Talos have uncovered a large-scale smishing campaign targeting toll road...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

IBM Aspera Faspex Flaw Allows Injection of Malicious JavaScript in Web UI

A significant security vulnerability has been identified in IBM Aspera Faspex 5, a popular...

Chinese APT Group Targets Ivanti VPN Vulnerabilities to Breach Networks

In a concerning report from cybersecurity firm TeamT5, it has been revealed that a...

CISA Issues 10 ICS Advisories Addressing Critical Vulnerabilities and Exploits

The Cybersecurity and Infrastructure Security Agency (CISA) has issued ten new Industrial Control Systems...