A new security flaw discovered over the summer affects billions of devices that use Bluetooth, including smartphones, tablets, laptops, and IoT devices. The flaw is known as BLESA (Bluetooth Low Energy Spoofing Attack) and affects all devices that use the Bluetooth Low Energy (BLE) protocol.

The BLE is a "lighter" version of the original Bluetooth (Classic) standard, designed to conserve battery powerwhile maintaining Bluetooth connections for as long as possible. BLE has been widely adopted over the past decade and is found in the majority of battery-powered devices due to the power savings it offers.
Due to the great popularity that this particular protocol seems to have, security researchers have frequently checked it for security gaps in recent years, often discovering serious vulnerabilities.
A team of seven Purdue University academics set out to investigate a part of the BLE protocol that plays a crucial role in everyday operations, but has rarely been analyzed for security issues.
The research focused on the “reconnection” process, an operation that occurs after two BLE devices have authenticated each other during pairing.
Reconnections occur when Bluetooth devices move out of range and then return to the area later. Normally, during reconnection, the two BLE devices would need to check each other's cryptographic keys to reconnect and continue exchanging data over BLE.

But as the Purdue research team found, the BLE protocol contained two systemic issues that have been identified in BLE software applications:
- Authentication upon device reconnect is optional and not mandatory.
- Authentication can potentially be bypassed if the user's device does not force the IoT device to authenticate the shared data.
These two issues allow a BLESA attack to occur. A nearby attacker bypasses reconnection verifications and sends fake data to a BLE device with incorrect information, inducing operators and automated processes to make incorrect decisions.
The Purdue researchers said they analyzed several software stacks that have been used to support BLE communications across various operating systems.
The researchers found that BlueZ (on Linux-based IoT devices), Fluoride (Android), and iOS BLE were all vulnerable to BLESA attacks, while BLE on Windows was secure.
As for Linux- based IoT devices , the BlueZ development team said it will remove the part of the code that makes devices vulnerable to BLESA attacks and instead, use code that implements proper reconnection procedures.
The downside to this scenario is that patching all vulnerable devices will be extremely difficult for system administrators, and patching some devices may not even be an option.
A piece of IoT that has been sold over the past decade does not come with a built-in update mechanism, meaning these devices will be exposed to attack.
Attackers can use denial-of-service to take devices offline and trigger a reconnect-on-demand mode, then perform a BLESA attack. Protecting BLE devices from disconnections and signal drops is impossible.
Based on previous BLE usage statistics, the research team believes that the number of devices using the vulnerable BLE software stacks is in the billions. For now, all that users of devices with the affected software can do is wait for the appropriate updates to be released.
