Top Bluetooth chip security flaw could put a billion devices at risk worldwide


- Security researchers Tarlogic found a hidden feature in the ESPC32 Bluetooth chip
- The affordable chip is found in millions of domestic IoT devices worldwide
- The flaw allowed malicious actors access to the devices and sensitive data coming through
A low-cost Bluetooth chip which allegedly powers millions of Internet of Things (IoT) devices around the world has a “hidden feature” that allows those who know of it, to run arbitrary commands, unlock additional functionalities, and even extract sensitive information from the devices.
Cybersecurity researchers at Tarlogic have claimed ESPC32 chips, which allow connectivity via WiFi or Bluetooth, “have hidden commands not documented by the manufacturer.”
“These commands would allow modifying the chips arbitrarily to unlock additional functionalities, infecting these chips with malicious code, and even carrying out attacks of identity theft of devices,” they said.
You may like
Obtaining confidential information
The ESP32 chip is built by a Chinese semiconductor company headquartered in Shanghai, called Espressif. It costs approximately $2 per unit and, according to the manufacturer, has been sold a billion times from its inception to 2023.
Tarlogic says that its affordability is one of the main reasons why it is so commonly found in Bluetooth IoT devices for domestic use.
Tarlogic first described the findings as a “backdoor”, but later backtracked on that terminology: “We would like to clarify that it is more appropriate to refer to the presence of proprietary HCI commands—which allow operations such as reading and modifying memory in the ESP32 controller—as a “hidden feature” rather than a “backdoor.”,” it said.
Stil, threat actors could use these commands to run supply chain attacks, hide backdoors in the chipset, or execute more sophisticated attacks, Tarlogic added. They could impersonate known devices to connect to mobile phones, computers, and smart devices, even when they’re in offline mode.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Tarlogic said the purpose is, “to obtain confidential information stored on them, to have access to personal and business conversations, and to spy on citizens and companies.”
We have reached out to Espressif for a comment and will update the article if we hear back.
You might also like
Security researchers Tarlogic found a hidden feature in the ESPC32 Bluetooth chip The affordable chip is found in millions of domestic IoT devices worldwide The flaw allowed malicious actors access to the devices and sensitive data coming through A low-cost Bluetooth chip which allegedly powers millions of Internet of Things…
Recent Posts
- Top Bluetooth chip security flaw could put a billion devices at risk worldwide
- Lego’s new Mario Kart set super-sizes Mario
- iPad Air M3 review: A modest update that’s still easy to recommend
- Six thoughts on Apple’s new M3 iPad Air
- Garmin owners were confused about 13.35 software update for Fenix 8, here’s what actually happened
Archives
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010