News: 1701895652

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Apple and some Linux distros are open to Bluetooth attack

(2023/12/06)


A years-old Bluetooth authentication bypass vulnerability allows miscreants to connect to Apple, Android and Linux devices and inject keystrokes to run arbitrary commands, according to a software engineer at drone technology firm SkySafe.

The bug, tracked as CVE-2023-45866, doesn't require any special hardware to exploit, and the attack can be pulled off from a Linux machine using a regular Bluetooth adapter, says Marc Newlin, who found the flaw and reported it to Apple, Google, Canonical, and Bluetooth SIG.

Newlin says he'll provide vulnerability details and proof-of-concept code at an upcoming conference but wants to hold off until everything is patched. The attack allows a nearby intruder to inject keystrokes and execute malicious actions on victims' devices, as long as they don't require a password or biometric authentication.

[1]

In a [2]GitHub post published on Wednesday, the bug hunter describes the security flaw thus:

"The vulnerabilities work by tricking the Bluetooth host state-machine into pairing with a fake keyboard without user-confirmation. The underlying unauthenticated pairing mechanism is defined in the Bluetooth specification, and implementation-specific bugs expose it to the attacker."

Regulars readers may remember Newlin from a similar set of Bluetooth flaws he uncovered in 2016. These, dubbed [3]MouseJack , exploited keystroke-injection vulnerabilities in wireless mice and keyboards from 17 different vendors.

CVE-2023-45866, however, is even older than MouseJack. Newlin says he tested a BLU DASH 3.5 running Android 4.2.2, which was released in 2012, and found it vulnerable to the flaw. In fact, there is no fix for Android 4.2.2-10 issue.

[4]

[5]

Google issued the following statement to Newlin: "Fixes for these issues that affect Android 11 through 14 are available to impacted OEMs. All currently-supported Pixel devices will receive this fix via December OTA updates." Here's the details published in the Android [6]security bulletin , with the flaw rated high severity.

[7]Hijack wireless mice, keyboards, with $15 of kit and 15 lines of code

[8]Weak session keys let snoops take a byte out of your Bluetooth traffic

[9]A year on, CISA realizes debunked vuln actually a dud and removes it from must-patch list

[10]Atlassian security advisory reveals four fresh critical flaws – in mail with dead links

While the issue was fixed in Linux in 2020, Newlin says ChromeOS is the only Linux-based operating system that enabled the fix. Other Linux distros including Ubuntu, Debian, Fedora, Gentoo, Arch and Alpine left it disabled by default. Ubuntu 18.04, 20.04, 22.04, 23.10 remain vulnerable, we're told.

[11]This patch mitigates the flaw in BlueZ.

The bug also affects macOS and iOS when Bluetooth is enabled and a Magic Keyboard has been paired with the vulnerable phone or computer. Critically, it works in Apple's LockDown mode, which the vendor claims can protect devices against sophisticated attacks.

[12]

Newlin disclosed the issue to Apple back in August. He told The Register that Apple did confirm his report, but hasn't shared a patch timeline for the vulnerability.

Apple did not respond to The Register 's inquiries. ®

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXD9HrQvEtNZ7GcdZQS4LwAAABI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://github.com/skysafe/reblog/tree/main/cve-2023-45866

[3] https://www.theregister.com/2016/02/24/hijack_wireless_mice_keyboards_with_15_of_kit_and_15_lines_of_code/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXD9HrQvEtNZ7GcdZQS4LwAAABI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXD9HrQvEtNZ7GcdZQS4LwAAABI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://source.android.com/docs/security/bulletin/2023-12-01

[7] https://www.theregister.com/2016/02/24/hijack_wireless_mice_keyboards_with_15_of_kit_and_15_lines_of_code/

[8] https://www.theregister.com/2023/11/30/bluetooth_bluffs_attacks_are_no/

[9] https://www.theregister.com/2023/12/06/dud_cve_removed/

[10] https://www.theregister.com/2023/12/06/atlassian_four_rce_cves/

[11] https://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/profiles/input?id=25a471a83e02e1effb15d5a488b3f0085eaeb675

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXD9HrQvEtNZ7GcdZQS4LwAAABI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



karlkarl

Firstly, I agree wholeheartedly with OpenBSD ripping bluetooth out. It is a pretty disgusting stack. It barely works consistently on any platform I have dabbled with.***

However, Bluetooth can't entirely be blamed for this; it is like blaming USB in general for the risk of plugging in and autorunning a dodgy .exe in the Windows XP days. Bluetooth is just a transport layer that carries the data, it is the dodgy HID drivers at the other end that have the flaw. The problem is that so many drivers that make up the Bluetooth ecosystem are so terribly written and curiously, I am not so sure why.

*** For things like Bluetooth headphones, you can actually get adapters that use bluetooth transparently. This might be a good compromise for some.

I.e https://www.amazon.co.uk/Bluetooth-MaedHawk-Microphone-Streaming-Headphones-Metal-Grey/dp/B086VZQG55

Korev

Google issued the following statement to Newlin: "Fixes for these issues that affect Android 11 through 14 are available to impacted OEMs.

In other words most Android users are on their own as the OEMs get bored of updating their phones so quickly...

PRR

OK, that explains the odd note I got from my university IT office this afternoon:

...you are using an outdated version of Android or iOS software for mobile devices. Effective February 9 (!!!) , Duo Mobile—the app for two-step login with Duo at {school}—will no longer support Android 10 (or older) and iOS 14 (or older). Please upgrade your mobile device’s Android or iOS software to stay secure and get the latest updates to Duo Mobile.

> ...most Android users are on their own as the OEMs get bored of updating their phones so quickly...

I understand your angst. But I am very trailing-edge, yet I looked around and my only 'fone with <=10 is the one I have not used in months, have not powered-up in weeks, am about ready to wipe and recycle. (I disabled the Duo on that 'fone anyway.) As I am also 500 feet out in the 5-mile woods I am not very afraid of BluTooth hackers, nor do I need 2FA very often.

When he got in trouble in the ring, [Ali] imagined a door swung open and
inside he could see neon, orange, and green lights blinking, and bats
blowing trumpets and alligators blowing trombones, and he could hear snakes
screaming. Weird masks and actors' clothes hung on the wall, and if he
stepped across the sill and reached for them, he knew that he was committing
himself to destruction.
-- George Plimpton