Bluetooth keystroke injection across platforms
Summary
Marc Newlin explains how faulty Bluetooth HID states enable unauthenticated keyboard input across platforms. CVE-2023-45866 affects Android, Linux, macOS and iOS. An ordinary Linux computer with a standard Bluetooth adapter was enough for the demonstration.
Ideas
- An attacker poses as a Bluetooth keyboard towards the target.
- Certain pairing paths accept HID devices without explicit user confirmation.
- Protocol options and implementation bugs combine in the vulnerability.
- Injected keystrokes have the rights of the logged-in user.
- With radio attacks, proximity replaces ordinary network reachability.
Insights
- Trust models for input devices deserve the same scrutiny as network protocols.
- Several independent implementations can adopt the same dangerous protocol assumption.
- Security modes help little if trusted input paths themselves remain attackable.
Facts
- BlueZ was only vulnerable when configured as discoverable or connectable.
Recommendations
- Install Bluetooth and operating system updates on all reachable devices.
- Disable Bluetooth or discoverability where no wireless peripherals are needed.
References
Links to the original source and the Web Archive open in a new tab.