A new Bluetooth security flaw has been discovered that would potentially allow an attacker to connect to a user device without authentication.
The Bluetooth Special Interest Group (SIG), the body responsible for Bluetooth standards, has confirmed vulnerabilities separately discovered by two teams of security researchers…
The organization issued a brief statement.
Apple protects against some forms of Bluetooth attack by requiring apps to ask user permission before a connection is initiated. You should only ever grant permission when you have a specific reason to allow an app to connect to a Bluetooth device, and are expecting it to ask.
Researchers at the École Polytechnique Fédérale de Lausanne (EPFL) and Purdue University have independently identified vulnerabilities related to Cross-Transport Key Derivation (CTKD) in implementations supporting pairing and encryption with both Bluetooth BR/EDR and LE in Bluetooth Specifications 4.0 through 5.0 […]
For this attack to be successful, an attacking device would need to be within wireless range of a vulnerable Bluetooth device supporting both BR/EDR and LE transports that supports CTKD between the transports and permits pairing on either the BR/EDR or LE transport either with no authentication (e.g. JustWorks) or no user-controlled access restrictions on the availability of pairing. If a device spoofing another device’s identity becomes paired or bonded on a transport and CTKD is used to derive a key which then overwrites a pre-existing key of greater strength or that was created using authentication, then access to authenticated services may occur. This may permit a Man In The Middle (MITM) attack between devices previously bonded using authenticated pairing when those peer devices are both vulnerable.
Vulnerability to so-called Man-In-The-Middle (MITM) attacks is less clear. With some of these, an attacker can impersonate a previously paired device, which would then be allowed to connect without user intervention. However, iOS has protections like app sandboxing, which may also mitigate against this attack method.
There’s nothing else we can do at this stage. Bluetooth SIG says that it is in contact with vendors, and will make recommendations on steps needed to protect against these flaws.
If any additional protection is needed on Apple devices, the Cupertino company would include these into a future security update.
The Bluetooth SIG is also broadly communicating details on this vulnerability and its remedies to our member companies and is encouraging them to rapidly integrate any necessary patches. As always, Bluetooth users should ensure they have installed the latest recommended updates from device and operating system manufacturers.
Two other Bluetooth security flaws were discovered last year, one of which was sufficiently dangerous that the official Bluetooth specification was changed in response. A further one was reported earlier this year.