A potential security issue has been discovered by cybersecurity researchers that has the capability to affect more than one billion devices.
According to researchers at the cybersecurity firm Tarlogic,Poland a hidden command has been foundcoded into a bluetooth chip installed in devices around the world. This secret functionality can be weaponized by bad actors and, according to the researchers, used as an exploit into these devices.
Using these commands, hackers could impersonate a trusted device and then connect to smartphones, computers, and other devices in order to access information stored on them. Bad actors can continue to utilize their connection to the device to essentially spy on users.
The bluetooth chip is called ESP32 and is manufactured by the China-based company Espressif. According to researchers, the ESP32 is "a microcontroller that enables WiFi and Bluetooth connection." In 2023, Espressif reported that one billion units of its ESP32 chip had been sold globally. Millions of IoT devices like smart appliances utilize this particular ESP32 chip.
Tarlogic researchers say that this hidden command could be exploited, which would allow "hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls." Tarlogic says that these commands are not publicly documented by Espressif.
Researchers with Tarlogic developed a new Bluetooth driver tool in order to aid in Bluetooth-related security research, which enabled the security firm to discover a total of 29 hidden functionalities that could be exploited to impersonate known devices and access confidential information stored on a device.
According to Tarlogic, Espressif sells these bluetooth chips for roughly $2, which explains why so many devices utilize the component over higher costing options.
As BleepingComputerreports, the issue is being tracked as CVE-2025-27840.
Topics Bluetooth Cybersecurity
Memorial Day home deals: Shop discounts on mattresses, Dyson vacuums, and moreBest PlayStation deal: Save $50 on the PS5 SlimThe cicadas aren't invading the U.S.Best PlayStation deal: Save $50 on the PS5 SlimWordle today: The answer and hints for May 28Best Amazon deal: The Samsung Galaxy Buds 2 are 53% off at AmazonBest PlayStation deal: Save $50 on the PS5 SlimBest gift card deals: Save up to 20% on Lyft, Taco Bell, DoorDash, and moreThe next batch of Samsung foldables will be the thinnest and lightest yetHuawei's 2023 global sales revenue hits nearly 98 billion dollars, up by 9.63% yBest Memorial Day deals: Amazon Memorial Day SaleDouyin launches independent shopping app as eNew Fitbit smartwatch has gaming and privacy featuresChina’s online video market shines with expanding short video capabilities · TechNodeMurray vs. Wawrinka 2024 livestream: Watch French Open for freeMemorial Day home deals: Shop discounts on mattresses, Dyson vacuums, and moreAlibaba to pour $1.1 billion into South Korean market in chase for growth · TechNodeVivo unveils X Fold3, the lightest and thinnest bookEvans vs. Rune 2024 livestream: Watch French Open for freeThe cicadas aren't invading the U.S. Marvel's 'The Falcon and the Winter Soldier' composer interview Anchor says Sen. Al Franken 'kissed and groped' her without consent South Carolina women's basketball team declines White House invite Elon Musk wept over his love life in front of a Rolling Stone reporter Twitter to start monitoring users outside of Twitter, will ban people affiliated with hate groups Tony the baby hippopotamus is our new prince, America Disney+ Star Wars x Simpsons short: 9 hidden Easter eggs Disney's 'real' lightsaber isn't quite as cool as it looks YouTube star Jake Paul moves into his $6.9 million Calabasas mansion Apple's macOS needs another update (yes, again) to fix vulnerabilities Small businesses had a brutal pandemic. Amazon's income tripled. 7 best places to find audiobooks to fill your ears with good reads Hillary Clinton saw 'Dear Evan Hansen' last night, met the cast, and signed a cast How to receive a full refund for your Peloton Tread+ and Tread Tom Brady is being compared to Judge Doom at the 2021 Kentucky Derby Basecamp fire grows as employees tweet they're leaving the company Sylvester Stallone accused of coercing teen into unwanted sex act in 1986 Bill and Melinda Gates are ending their 27 Watch Royal Marines fly over the sea onto a military ship using a jetsuit Do you have 600 or more Twitter followers? You can use Twitter Spaces now.
2.7776s , 10110.34375 kb
Copyright © 2025 Powered by 【Poland】,Unobstructed Information Network