bk99.de entertain the web since 1997

Bluetooth keystroke injection across platforms

Summary

Marc Newlin explains how faulty Bluetooth HID states enable unauthenticated keyboard input across platforms. CVE-2023-45866 affects Android, Linux, macOS and iOS. An ordinary Linux computer with a standard Bluetooth adapter was enough for the demonstration.

Ideas

  • An attacker poses as a Bluetooth keyboard towards the target.
  • Certain pairing paths accept HID devices without explicit user confirmation.
  • Protocol options and implementation bugs combine in the vulnerability.
  • Injected keystrokes have the rights of the logged-in user.
  • With radio attacks, proximity replaces ordinary network reachability.

Insights

  • Trust models for input devices deserve the same scrutiny as network protocols.
  • Several independent implementations can adopt the same dangerous protocol assumption.
  • Security modes help little if trusted input paths themselves remain attackable.

Facts

  • BlueZ was only vulnerable when configured as discoverable or connectable.

Recommendations

  • Install Bluetooth and operating system updates on all reachable devices.
  • Disable Bluetooth or discoverability where no wireless peripherals are needed.

References

Read the original article

Search the Web Archive