
A new attack called Bluetooth BIASallows attackers to trick an already connected device and perform successful authentication without having the connection key used for pairing.
According to a study released by researchers at the École Polytechnique Fédérale de Lausanne (EPFL), titled BIAS: Bluetooth Impersonation AttackS, the Bluetooth standard contains certain vulnerabilities that allow malicious actors to exploit them and "spoof" a device, thus obtaining a secure connection.
Bluetooth BIAS Attack
The Bluetooth BIAS attack can be carried out thanks to flaws in the Bluetooth specification , so any Bluetooth device compliant with the standards is vulnerable.
For the attack to be successful, the attacking device must be within range of a vulnerable Bluetooth device that had previously established a BR/EDR connection with a remote device with a Bluetooth address known to the attacker.
The research published by EPFL mentions two attack methods. The attacker needs a remote device that has been previously paired, but without support for Secure Connections, in order to degrade authentication security.
This would allow him, using the BIAS method, to gain access to the device, unless the device he is attacking is in Secure Connections mode exclusively.

If the attack is successful, the attacker can authenticate with the remote device. If the attacked device does not authenticate with the attacker's device, it will still result in a full authentication notification, even though the connection key is not shared.
As a result, an attacker completes the secure connection setup while impersonating Bluetooth devices, without needing to know and validate the long-term key shared between victims.
How will you protect yourself?
To fix the vulnerability, the Bluetooth SIG is set to release an update to the Bluetooth core specification.
The update will be available with a future specification revision, but until then, the Bluetooth SIG recommends reducing the encryption key length to below 7 bytes.
