A team of security researchers has discovered a critical security vulnerability in the Bluetooth wireless communication protocol, which leaves millions of devices vulnerable to attacks.
Daniele Antonioli from the Singapore University of Technology and Design, Nils Ole Tippenhauer from the CISPA Helmholtz Center for Information Security, and Kasper Rasmussen from the Department of Computer Science University of Oxford published a paper titled “The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation Of Bluetooth BR/EDR,” in which they reveal a new major security flaw in Bluetooth.

According to researchers, the new vulnerability in Bluetooth could leave millions of devices using the protocol exposed to a new type of attack called KNOB (originally from Key Negotiation Of Bluetooth). The attack allows attackers to bypass the Bluetooth pairing process and spy on the data shared between devices, even if they have been paired.
The official KNOB page states:
The KNOB attack is possible due to flaws in the Bluetooth specification. Therefore, any Bluetooth-compatible device can be vulnerable. We have performed KNOB attacks on more than 17 unique Bluetooth chips (in 24 different devices), so far. We were able to test chips from manufacturers Broadcom, Qualcomm, Apple, Intel and Chicony. All devices we tested were vulnerable to the KNOB attack
As it turns out, it's a major security flaw that affects all Bluetooth-enabled devices.
So researchers had to coordinate the disclosure with the manufacturers, so that they had time to fix the bug and release the necessary security updates to users. The vulnerability was discovered in November 2018 and has been documented as CVE-2019-9506.
Apple, Intel, and Microsoft have already released the necessary update that fixes the Bluetooth vulnerability.
However, security researchers warn that if your device hasn't been updated since late 2018, it is vulnerable.
_________________________
- iPhone or Mac: two different ways of hacking
- Digital steganography: What is digital steganography?
- Microsoft officially retires MSDN magazine
