Mashable 03月11日
Secret commands found in Bluetooth chip used in a billion devices
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

网络安全公司Tarlogic的研究人员发现,全球数十亿设备中安装的蓝牙芯片ESP32存在一个潜在的安全问题。该芯片由中国公司乐鑫科技(Espressif)制造,被发现隐藏了一个秘密指令,可能被恶意行为者利用,模拟可信设备并连接到智能手机、电脑等设备,从而访问存储在其中的信息,甚至监视用户。该漏洞影响广泛,包括智能家电等数百万物联网设备。研究人员已将此问题追踪为CVE-2025-27840。

⚠️ ESP32芯片由乐鑫科技制造,被广泛应用于全球的物联网设备中,但研究人员发现了该芯片中隐藏的未公开指令,这些指令为恶意攻击者提供了可乘之机。

🛡️ 通过利用这些隐藏指令,攻击者可以模拟可信设备,绕过代码审计控制,从而永久感染敏感设备,例如手机、电脑、智能锁或医疗设备等。

🕵️ Tarlogic研究人员开发了一种新的蓝牙驱动工具,发现了29个隐藏功能,这些功能可被利用来模拟已知设备并访问设备上存储的机密信息。

A potential security issue has been discovered by cybersecurity researchers that has the capability to affect more than one billion devices.

According to researchers at the cybersecurity firm Tarlogic, a hidden command has been found coded into a bluetooth chip installed in devices around the world. This secret functionality can be weaponized by bad actors and, according to the researchers, used as an exploit into these devices.

Using these commands, hackers could impersonate a trusted device and then connect to smartphones, computers, and other devices in order to access information stored on them. Bad actors can continue to utilize their connection to the device to essentially spy on users.

The bluetooth chip is called ESP32 and is manufactured by the China-based company Espressif. According to researchers, the ESP32  is "a microcontroller that enables WiFi and Bluetooth connection." In 2023, Espressif reported that one billion units of its ESP32 chip had been sold globally. Millions of IoT devices like smart appliances utilize this particular ESP32 chip.

Tarlogic researchers say that this hidden command could be exploited, which would allow  "hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls." Tarlogic says that these commands are not publicly documented by Espressif.

Researchers with Tarlogic developed a new Bluetooth driver tool in order to aid in Bluetooth-related security research, which enabled the security firm to discover a total of 29 hidden functionalities that could be exploited to impersonate known devices and access confidential information stored on a device. 

According to Tarlogic, Espressif sells these bluetooth chips for roughly $2, which explains why so many devices utilize the component over higher costing options.

As BleepingComputer reports, the issue is being tracked as CVE-2025-27840.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

蓝牙芯片 安全漏洞 ESP32 乐鑫科技 物联网安全
相关文章