A team of researchers from the Center for Education and Research in Information Assurance and Security (CERIAS) at Purdue University recently discovered a flaw that affects many IoT devices that use Bluetooth and can even lead to spoofing attacks. Bluetooth Low Energy (BLE) is the most widely used low-energy communication protocol for mobile and IoT devices. Consulting firm ABI estimates that sales of Bluetooth Low Energy (BLE) devices will triple by 2023, exceeding 1.5 billion in annual sales.
BLE devices rely on pairing, a critical process, to build “trust” between two devices the first time they connect. After pairing, reconnection between BLE devices is often transparent to the user.
The flaw lies in the reconnection processes for BLE devices that have already been paired. And reconnections happen frequently in typical usage scenarios, according to Jianliang Wu, a doctoral student in the PurSec Lab at Purdue University and one of the project's principal investigators.

Bluetooth devices often move out of range and then return to a range, while re-establishing a connection with devices that were already paired. All of this happens without user notification. The research focuses on this very reconnection process. Specifically, the researchers sought to examine the reconnection process for potential flaws and initially theoretically analyzed the reconnection process, performing formal verification of the connection procedures proposed in the latest BLE specification.
The research revealed two critical BLE design weaknesses:
- For some BLE devices, authentication upon device reconnect is optional and not mandatory.
- For other BLE devices, authentication can potentially be bypassed if the user's device fails to force the IoT device to authenticate the transferred data.
After discovering the design flaws in the BLE specification, the researchers analyzed key BLE stack implementations, including the BLE protocol stacks on Linux, Android, iOS, and Windows, to see if the devices were vulnerable to the security flaws. Three of the devices tested were likely vulnerable, as they failed to ensure that the connected IoT device authenticated its data and accepted unauthorized data.
The researchers said that this flaw has a broad impact on major platforms that support BLE communications, including Linux, Android , and iOS. They also added that according to a recent study, over 1 billion BLE devices do not use application-level security, which could provide a second line of defense. In addition, at least 8,000 Android BLE apps with about 2.5 billion installs read data from BLE devices in plaintext. Similar numbers may apply to iOS. The researchers concluded that this flaw could affect over 1 billion BLE devices and over 15,000 BLE apps. The researchers also reported their research results to Google and Apple , who confirmed the flaw. The research results will be formally presented at the 14th USENIX Workshop on Offensive Technologies (WOOT 2020) in August.

The researchers also reported that attackers could perform spoofing attacks and spoof the IoT device, forge malicious data corresponding to it, and send the fake data to the user's device. Specifically, the design weakness and errors allow attackers to bypass authentication in BLE reconnections, which can lead to spoofing attacks against the user's devices. In addition, attackers can easily spoof all IoT device data that is not protected by application-level authentication.
This could have several implications, according to the researchers. For example, malicious keystrokes could be entered into the smartphone or desktop when reconnected to a BLE keyboard. Additionally, a fake glucose level value could be injected into the smartphone while the user is reading data from a BLE monitor that displays glucose levels. Fake fitness data could be retrieved from the user when reconnected to a fitness tracker.
To prevent potential spoofing attacks, both the BLE specification and current BLE stack implementations on Linux, Android, and iOS need to be updated to ensure the reconnection process. Finally, users should install the latest firmware version to apply the required security patches and fix the bugs. It is worth mentioning that Apple has already fixed the issue in iOS 13.4 and iPadOS 13.4.
