HomeSecurityNew Bluetooth vulnerability leaks Passkeys during pairing

New Bluetooth vulnerability leaks Passkeys during pairing

A recently discovered vulnerability in Bluetooth technology, known as CVE-2020-26558, poses a significant security risk to devices supporting various Bluetooth core specifications.

See also: Ultimate Ears launches the new MINIROLL Bluetooth speaker

Bluetooth passkey vulnerability

This vulnerability, known as “Impersonation in the Passkey Entry Protocol”, is a serious concern for devices based on the Passkey Entry. It affects BR/EDR secure simple pairings, secure connections, and LE connections, highlighting the importance of security in these processes!

The vulnerability exists in specifications ranging from version 2.1 to 5.4 for BR/EDR and from version 4.2 to 5.4 for LE secure connections.

It allows a man-in-the-middle (MITM) to exploit the pairing process by responding to a starting device with a public key whose X coordinate matches that of the peer device.

Through edited responses, an attacker can identify the password used during the pairing process. This can lead to an authentication process that affects both the initiating and responding devices.

According to the report , to successfully exploit the vulnerability, an attacker must be within wireless range of two vulnerable Bluetooth devices initiating pairing or connection. The attack specifically targets scenarios where an exchange of BR/EDR or LE IO capabilities results in the selection of the passkeys pairing process.

See also: Bluetooth 6.0 officially released with new features

New Bluetooth vulnerability leaks Passkeys during pairing

To mitigate this risk, the Bluetooth 5.4 core specification proposes that devices should fail the pairing process if the X coordinate of a peer's public key matches that of the local device, unless a debug key is used. This check is made mandatory in the Bluetooth Core 6.0 specification .

Experts recommend that manufacturers and developers adhere to these guidelines and update applications to comply with the latest specifications. Ensuring that devices reject public keys with corresponding X coordinates can prevent potential MITM attacks and improve overall security.

The Bluetooth Special Interest Group (SIG) emphasizes the importance of keeping up-to-date with security protocols to protect against vulnerabilities like CVE-2020-26558. Users are encouraged to regularly update their devices and learn about security updates released by device manufacturers.

As Bluetooth technology evolves, it is critical to maintain strong security measures to protect personal data and ensure secure wireless communication.

See also: How to connect Beats headphones to a Bluetooth device

Bluetooth vulnerabilities have become a major concern in the era of wireless connectivity. Weak spots in the Bluetooth protocol can allow malicious actors to intercept data, launch network attacks, or even gain access to personal devices. It is important for users to keep their devices up to date and implement strong security settings to prevent such threats. In addition, it is a good idea to avoid connecting to unknown networks and enable Bluetooth only when necessary.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS