A vulnerability in the Bluetooth stacks of Linux, macOS, Android, and iOS allows for key press substitution

Marc Newlin, who discovered the MouseJack vulnerability seven years ago, has revealed details about a similar vulnerability (CVE-2023-45866) affecting Bluetooth stacks on Android, Linux, macOS, and iOS. This vulnerability allows for keypress injection through simulation of activity from a Bluetooth-connected input device. With access to keyboard input, an attacker can perform actions such as executing commands on the system, installing applications, and redirecting messages.

The vulnerability arises from the fact that host HID (Human Interface Device) drivers for Bluetooth devices have a mode that allows a remote peripheral device to create and establish encrypted connections without authentication. Among other things, devices connected in this manner can transmit keyboard messages, and the HID stack will process them, enabling a remote HID message injection attack without user involvement. The attack can be conducted with the attacker being up to 100 meters away from the victim.

The mechanism for pairing devices without authentication is defined in the Bluetooth specification and depending on Bluetooth stack settings, it allows a device to connect without user confirmation. In Linux, when using the BlueZ Bluetooth stack for hidden pairing, the Bluetooth adapter must be in discoverable and connectable mode. In Android, simply enabling Bluetooth support is sufficient. In iOS and macOS, Bluetooth must be enabled, and a wireless keyboard must be connected to carry out the attack.

The input injection capability has been demonstrated on Ubuntu 18.04, 20.04, 22.04, and 23.10 with a Bluetooth stack based on the Bluez package. ChromeOS is not susceptible to this vulnerability as its Bluetooth stack settings do not allow connections without authentication. In Android, the vulnerability affects devices with platform versions from 4.2.2 to 14. In macOS, the vulnerability has been demonstrated on a 2022 MacBook Pro with an Apple M2 CPU and macOS 13.3.3, and on a 2017 MacBook Air with an Intel CPU and macOS 12.6.7. In iOS, the vulnerability was demonstrated on an iPhone SE with iOS 16.6. Enabling Lockdown mode does not protect against attacks on macOS and iOS.

In Linux, the vulnerability has been fixed in the Bluez codebase by setting the "ClassicBondedOnly" option to true, enabling a secure mode that allows connections only after pairing. Previously, it was set to false, which compromised security to address compatibility issues with some input devices.

In the Fluoride Bluetooth stack used in recent Android releases, the vulnerability has been addressed by requiring authentication for all encrypted connections. fixes for Android have only been made for branches 11-14. The vulnerability has been fixed in the December firmware update for Pixel devices. It remains unpatched for Android releases from 4.2.2 to 10.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster