Bluetooth: discovery of a critical vulnerability – updates are in progress



[ad_1]

Millions of Devices Affected

Israeli researchers have discovered a new Bluetooth vulnerability affecting millions of devices. Including branded products such as Intel, Apple and Qualcomm. Attackers could thus connect between the pairing devices and manipulate the traffic. Updates are already in progress.

  Millions of devices are concerned with a new Bluetooth vulnerability.
Millions of devices are concerned with a new Bluetooth vulnerability. (Source: Wavebreakmedia / depositphotos.com)

Millions of devices are affected by critical vulnerability in the process of Bluetooth pairing. According to the Computer Emergency Response Team (CERT) of Carnegie Mellon University in Pittsburgh (United States), two Israeli researchers from the Technical University of Toronto Israel (Technion) have now discovered this. Affected by the vulnerability are also Intel, Apple and Qualcomm devices.

Driver

For computer hardware and peripherals to work properly, the appropriate drivers should not be missed. These create an interface between the hardware and the operating system.

A problem with the cryptographically secure pairing mechanism allows unauthorized third parties to connect to and manipulate data traffic. This is made possible by insufficient control during the first "key exchange", which is usually secured by the Elliptic-Curve Diffie-Hellman (ECDH) security protocol.

Threat in weak practice

Even though the vulnerability of Intel or CERT is clbadified as critical, the attacker has only a short time to conduct the attack on the mentioned vulnerability. Because only during the first connection setup shows the vulnerability. In addition, the attacker must be in the immediate vicinity of the devices concerned.

Current Fraud Alerts – Phishing, Spam Mails, Accounts and Company Theme False invoices by email, profit reports by SMS or WhatsApp Trojan. On this overview page, we are collecting current security warnings around the topics of phishing, spam, fraud and Abofallen. Click here

Nevertheless, the updates are put in place by the manufacturers. Apple has already integrated the updates into operating system versions macOS High Sierra 10.13.5, iOS 11.4, watchOS 4.3.1 and tvOS 11.4. Intel also offers an update of its Bluetooth drivers. The Microsoft Bluetooth stack should not be affected. More fraud warnings and more common security messages can be found in our news-related ticker.

Popular scams: How to cheat the fraudsters in the net

8 Entries

Attention! These scams are trying to surpbad you in the net.

Watch now

Article information

This article was used with keywords
Bluetooth, security and current fraud warnings provided.

Links to the article

[ad_2]
Source link