Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

Researchers Release PoC Tool Targeting BrakTooth Bluetooth Vulnerabilities

The United States Cybersecurity and Infrastructure Security Agency (CISA) this week warned on proof-of-concept (PoC) code for the BrakTooth Bluetooth vulnerabilities now being publicly available.

The United States Cybersecurity and Infrastructure Security Agency (CISA) this week warned on proof-of-concept (PoC) code for the BrakTooth Bluetooth vulnerabilities now being publicly available.

BrakTooth is the name researchers with the Singapore University of Technology and Design gave to a set of roughly two dozen vulnerabilities in commercial Bluetooth Classic (BT) stacks and which affect system-on-chips (SoCs) running Bluetooth 3.0 + HS to Bluetooth 5.2.

The bugs could be exploited to cause denial of service (DoS) conditions, through crash of deadlock, and, in some cases, could also lead to arbitrary code execution. Exploitation of these flaws requires for the attacker to be within Bluetooth range of a vulnerable device.

In an August paper detailing the security holes, the researchers said they had identified 1,400 affected products, but also noted that the actual number could be much higher, given that the BT stack is often shared across multiple products. Overall, millions of devices are likely vulnerable.

After PoC code exploiting BrakTooth was published earlier this week, CISA urged manufacturers, vendors, and developers to review the code and apply the necessary updates or workarounds to their vulnerable Bluetooth System-on-a-Chip (SoC) applications as soon as possible.

“On November 1, 2021, researchers publicly released a BrakTooth proof-of-concept (PoC) tool to test Bluetooth-enabled devices against potential Bluetooth exploits using the researcher’s software tools. An attacker could exploit BrakTooth vulnerabilities to cause a range of effects from denial-of-service to arbitrary code execution,” CISA said.

Advertisement. Scroll to continue reading.

Related: BrakTooth: New Bluetooth Vulnerabilities Could Affect Millions of Devices

Related: CISA Lists 300 Exploited Vulnerabilities That Organizations Need to Patch

Related: CISA Raises Alarm on Critical Vulnerability in Discourse Forum Software

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.